Bug 2498310 (CVE-2026-55471)
| Summary: | CVE-2026-55471 ca.uhn.hapi.fhir/org.hl7.fhir.utilities: HAPI FHIR XsltUtilities: XML External Entity injection allows local file disclosure and SSRF | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | anujha, asoldano, bbaranow, bmaxwell, bstansbe, dlofthou, fmongiar, istudens, ivassile, iweiss, janstey, jnethert, mosmerov, msvehla, nwallace, pberan, pesilva, pjindal, pmackay, rstancel, thjenkin, vdosoudi |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the HAPI FHIR `XsltUtilities` component. The `saxonTransform` functions within this utility do not adequately restrict external entity access when processing XML. This oversight allows an attacker, who can control or tamper with the XML data being transformed, to inject malicious XML External Entities (XXE). Successful exploitation can lead to local file disclosure, enabling the attacker to read sensitive files from the system. Additionally, it can result in Server-Side Request Forgery (SSRF), where the attacker can force the system to make requests to arbitrary network resources, potentially exposing internal network information or cloud metadata.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-07-08 22:03:21 UTC
This issue has been addressed in the following products: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 Via RHSA-2026:54776 https://access.redhat.com/errata/RHSA-2026:54776 |