A vulnerability labeled as problematic has been found in hapifhir HAPI FHIR up to 6.9.10. The affected element is the function
readArray/readObject of the file org.hl7.fhir.utilities.json.parser.JsonParser of the component JSON utility parser. The manipulation results in improper input validation.
This vulnerability is identified as CVE-2026-62295. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.