The Lab · 2026-04-20 16:23:13 · GitHub Issues
A high-severity vulnerability, CVE-2026-24880, has been detected in the core Apache Tomcat library embedded within multiple HAPI FHIR Spring Boot sample projects. This critical security flaw resides in the `tomcat-embed-core-10.1.52.jar` file, a foundational component for running Java web applications. The vulnerabilit...
The Lab · 2026-04-20 16:23:15 · GitHub Issues
A newly disclosed medium-severity vulnerability, CVE-2026-22740, has been detected within the widely used `spring-web-6.2.12.jar` library. This security flaw is embedded in the core dependency chain of the HAPI FHIR project, a critical open-source framework for healthcare data interoperability. The vulnerability's pres...
The Lab · 2026-04-20 16:23:16 · GitHub Issues
Spring Framework 的一个核心组件被标记存在安全缺陷。CVE-2026-22741,一个低严重性漏洞,已在 `spring-webmvc-6.2.12.jar` 库中被检出。该漏洞并非孤立事件,其影响已渗透至一个关键的医疗数据互操作性项目——HAPI FHIR 的多个核心模块和测试套件中。
漏洞库 `spring-webmvc-6.2.12.jar` 是 Spring Web MVC 框架的一部分,广泛用于构建 Java Web 应用程序。扫描结果显示,该漏洞文件路径遍布 HAPI FHIR 项目的至少十个不同的依赖文件(pom.xml),包括其 JPA 服务器基础模块 (`hapi-fhir-jpaserver-b...