CVE-2026-34359 is a critical vulnerability affecting HAPI FHIR (hl7_fhir_core) versions prior to 6.9.4, where improper URL validation in ManagedWebAccessUtils.getServer() can lead to credential disclosure. Rated 9.1 CRITICAL, this flaw allows an unauthenticated attacker to obtain sensitive authentication credentials (Bearer tokens, Basic auth, API keys) by redirecting an HTTP client to an attacker-controlled domain that mimics a legitimate server URL prefix. The attack vector is network-based with low complexity and no user interaction required, resulting in high confidentiality and integrity impacts. While not currently listed in CISA's KEV catalog or having public exploit code, it is on a "Hot List" and has received minimal community discussion, indicating potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.9.4CPE matchmatch criteria | cpe:2.3:a:hapifhir:hl7_fhir_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.