Skip to main content

New research: Apex vs Claude Code Security vs Codex Security on the same codebase.

Free FHIR vulnerability scan

Get a free FHIR vulnerability scan funded by Cantina

Find authorization, PHI exposure, and API risks in the FHIR workflow closest to launch. Apex investigates, and Cantina security experts verify every finding.

Research
6 public FHIR advisories
Validation
Benchmarked against expert human auditors
Ecosystem
Supporting CMS Health Tech Ecosystem participants
“Cantina is the first platform we have used that carries the work through from finding an issue to driving the fix, and it lets my team operate like one far larger than it is. We keep finding new uses for it across our security program.”
Matt Mock Chief Information Security Officer

Claim your vulnerability scan

Tell us about your FHIR workflow

Takes a minute. A Cantina team member will follow up with a clear next step.

Fit, scope, timing, and availability are confirmed after qualification.

Applications remain private Privacy Policy

Scan process

From application to verified fixes

One focused vulnerability scan. Three clear steps.

  1. 01

    Share your workflow

    Tell us what you are launching and where you want the scan focused.

  2. 02

    We run the scan

    Apex investigates the authorized environment, and Cantina security experts validate every finding.

  3. 03

    Fix and verify

    Receive prioritized fixes, then have Cantina verify that the remediation holds.

Apex FHIR research

Six CVEs in one widely used FHIR server

Apex, Cantina’s autonomous OffSec agent, traced authenticated requests across OAuth discovery, credentialed data exchange, import and export jobs, and the analytical warehouse. The investigation led to six public security advisories.

Pathling security research High severity
  1. CVE-2026-47664

    01

    TrustLaunder

    A caller-controlled URL could receive OAuth credentials and place attacker-controlled data in the analytical warehouse.

  2. CVE-2026-47663 / 47660

    02

    Authorization and OAuth boundaries

    Scope enforcement and OAuth discovery paths exposed access beyond the workflow’s intended trust boundary.

  3. CVE-2026-47662 / 47661 / 47659

    03

    Bulk Data and warehouse access

    Export, import, and staging paths could expose bearer tokens or reach patient records outside the intended directory.

Disclosed, fixed, and public

Scan your FHIR workflow before launch

Claim your free vulnerability scan