On May 26, 2025, the OpenMRS project published a critical security advisory for openmrs-module-fhir2, tracked as CVE-2025-46823, affecting versions prior to 2.5.0. The advisory was published through the project’s own community channel (OpenMRS Talk), consistent with an actively maintained open-source security-disclosure process — the vulnerability was found, disclosed, and patched through the same community governance that maintains the rest of the platform.
This is cited to make a narrow point: an actively maintained FHIR module is not the same thing as a fully hardened one. Treat “maintained” and “security-audited to acute-care standard” as two separate claims that both need verifying before any production use.
Sources
- OpenMRS Talk, “OpenMRS Critical Security Advisory 2025-05-26”. The project’s own advisory, naming CVE-2025-46823 and the affected version range.