Skip to content

[SECURITY] Fix status for CISA ICSMA-26-253-01 CVEs (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578) in OIE 4.6.0? #440

Description

@Huggy56

Hi,
I recently came across this article reporting three High-severity vulnerabilities in NextGen Mirth Connect, and since OIE forks from the last open-source release (4.5.2), I'd like to ask about their fix status in OIE.

CISA advisory ICSMA-26-253-01 lists three High-severity CVEs in Mirth Connect 4.5.2, which OIE forks from. Could you clarify their fix status in OIE (specifically 4.6.0)?

Existing work (#361 metadata-search SQLi, #408/#406 HL7 strict-parser XXE) seems to target different components, and I couldn't find any PR or advisory covering these three specifically.

Questions: Are they fixed in 4.6.0 (if so, which PRs)? If not, is a fix planned, and any recommended mitigations meanwhile?

Refs: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01 · https://seclists.org/oss-sec/2026/q3/715 · https://www.databreachtoday.com/nextgen-mirth-connect-flaws-expose-downstream-system-logins-a-32789

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions