GHSA-vr79-8m62-wh98
CRITICALCVE-2026-34361The FHIR Validator HTTP service exposes an unauthenticated /loadIG endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined with a startsWith() URL prefix matching flaw in the credential provider (ManagedWebAccessUtils.getServer()), an attacker can steal authentication tokens (Bearer, Basic, API keys) configured for legitimate FHIR servers by registering a domain that prefi
- Affected
- < 6.9.4
- Fixed in
- 6.9.4
- Weakness
- CWE-522
- Published
- 2026-03-30
- Source
- github