CVE-2026-70469
- EPSS 0.37%
- Veröffentlicht 16.09.2026 19:38:42
- Zuletzt bearbeitet 21.09.2026 13:42:42
Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple...
CVE-2026-81866
- EPSS 0.4%
- Veröffentlicht 16.09.2026 19:38:04
- Zuletzt bearbeitet 21.09.2026 13:38:18
Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Connector configu...
CVE-2026-82561
- EPSS 0.26%
- Veröffentlicht 16.09.2026 19:37:20
- Zuletzt bearbeitet 21.09.2026 13:54:21
Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. ...
CVE-2026-86089
- EPSS 0.29%
- Veröffentlicht 16.09.2026 19:35:01
- Zuletzt bearbeitet 21.09.2026 14:00:59
Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the tar...
CVE-2026-87976
- EPSS 0.39%
- Veröffentlicht 16.09.2026 19:32:56
- Zuletzt bearbeitet 21.09.2026 14:14:51
Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as fil...
CVE-2026-68981
- EPSS 0.32%
- Veröffentlicht 03.08.2026 19:59:58
- Zuletzt bearbeitet 05.08.2026 14:59:30
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output,...
CVE-2026-68980
- EPSS 0.26%
- Veröffentlicht 03.08.2026 19:58:56
- Zuletzt bearbeitet 05.08.2026 14:59:19
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context...
CVE-2026-62354
- EPSS 0.31%
- Veröffentlicht 03.08.2026 19:57:44
- Zuletzt bearbeitet 10.08.2026 14:28:56
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read ac...
CVE-2026-68979
- EPSS 0.35%
- Veröffentlicht 03.08.2026 19:56:11
- Zuletzt bearbeitet 05.08.2026 14:59:03
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referen...
CVE-2026-44914
- EPSS 0.29%
- Veröffentlicht 22.06.2026 07:38:01
- Zuletzt bearbeitet 24.06.2026 05:17:28
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privilege...