VYPR

ePA3-Service-OpenSource

by Fbeta GmbH

CVEs (4)

  • CVE-2026-52723CriAug 18, 2026
    risk 0.52cvss 9.1epss

    ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU server certificate validation in app/vau/VAUProtokoll.py without anchoring the…

  • CVE-2026-50578HigAug 18, 2026
    risk 0.42cvss 7.5epss

    ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration disables TLS certificate verification for both ePA connections in app/vau/VAUProtokoll.py and Konnektor…

  • CVE-2026-50577HigAug 18, 2026
    risk 0.41cvss 7.4epss

    ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter unchanged in app/vau/VAUProtokoll.py while constructing VAU messages. The frozen…

  • CVE-2026-50576MedAug 18, 2026
    risk 0.37cvss 6.8epss

    ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration does not neutralize CRLF characters in values used by app/vau/VAUProtokoll.py to construct VAU inner HTTP…