Skip to content

Prevent XML xxe on Strict HL7 parsing - #406

Closed
mgaffigan wants to merge 2 commits into
OpenIntegrationEngine:mainfrom
mgaffigan:fix/hl7-permits-xml-by-default
Closed

mgaffigan wants to merge 2 commits into
OpenIntegrationEngine:mainfrom
mgaffigan:fix/hl7-permits-xml-by-default

Conversation

@mgaffigan

Copy link
Copy Markdown
Contributor

Avoids any possibility of XXE by not accepting XML input on a channel to receive HL7. Turns the message into an error - just as it would be for any other invalid format.

ER7Serializer error
ERROR MESSAGE: Error converting ER7 to XML
ca.uhn.hl7v2.parser.EncodingNotSupportedException: Determine encoding for message. The following is the first 50 chars of the message for reference, although this may not be where the issue is: <?xml version="1.0"?>
...

Breaking change for anyone relying on being able to send XML to a channel configured to receive HL7. Opt-out of the new behavior by toggling "Allow XML" in the datatype properties.

image

Thanks to Samuel Paschuan for reporting the issue.

@github-actions

github-actions Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Test Results

124 files  ±0  124 suites  ±0   2m 46s ⏱️ +48s
700 tests +2  700 ✅ +2  0 💤 ±0  0 ❌ ±0 
724 runs  +2  724 ✅ +2  0 💤 ±0  0 ❌ ±0 

Results for commit dd17abb. ± Comparison against base commit 1e87457.

♻️ This comment has been updated with latest results.

Message message = null;
source = source.trim();

if (source.length() > 0 && source.charAt(0) == '<') {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Non-blocking - How can this be documented in the release notes?

mgaffigan and others added 2 commits September 23, 2026 15:58
Signed-off-by: Mitch Gaffigan <mitch.gaffigan@comcast.net>
Signed-off-by: Jon Bartels <jonathan.bartels@gmail.com>
@jonbartels
jonbartels force-pushed the fix/hl7-permits-xml-by-default branch from 3083a72 to dd17abb Compare September 23, 2026 19:58
@mgaffigan mgaffigan closed this Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4.6.x CVE Fixes A quick way to organize a batch of CVE issues for 4.6.x, Sept 2026

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants