Apache / Apache Nifi
47 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-70469 | Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-81866 | Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration | LOW | 0.5 | Sep 16, 2026 |
| CVE-2026-82561 | Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods | MEDIUM | 5.9 | Sep 16, 2026 |
| CVE-2026-86089 | Apache NiFi: Missing Process Group Authorization for Connector Migration | LOW | 2.3 | Sep 16, 2026 |
| CVE-2026-68981 | Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests | HIGH | 8.8 | Aug 3, 2026 |
| CVE-2026-68980 | Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion | LOW | 2.3 | Aug 3, 2026 |
| CVE-2026-62354 | Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests | HIGH | 7.7 | Aug 3, 2026 |
| CVE-2026-68979 | Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates | MEDIUM | 5.9 | Aug 3, 2026 |
| CVE-2026-44914 | Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents | HIGH | 7.5 | Jun 22, 2026 |
| CVE-2026-44911 | Apache NiFi: Incorrect Authorization for Configuration Verification Requests | LOW | 2.3 | Jun 22, 2026 |
| CVE-2026-44913 | Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL | MEDIUM | 5.2 | Jun 22, 2026 |
| CVE-2026-54665 | Apache NiFi: Missing Validation for Proxy Host Headers | MEDIUM | 6.3 | Jun 22, 2026 |
| CVE-2026-39816 | Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService | HIGH | 7.5 | May 8, 2026 |
| CVE-2026-25903 | Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates | HIGH | 8.7 | Feb 17, 2026 |
| CVE-2025-66524 | Apache NiFi: Deserialization of Untrusted Data in GetAsanaObject Processor | HIGH | 7.5 | Dec 19, 2025 |
| CVE-2025-27017 | Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record | MEDIUM | 6.9 | Mar 12, 2025 |
| CVE-2024-56512 | Apache NiFi: Missing Complete Authorization for Parameter and Service References | LOW | 2.1 | Dec 28, 2024 |
| CVE-2024-52067 | Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log | MEDIUM | 6.9 | Nov 21, 2024 |
| CVE-2024-45477 | Apache NiFi: Improper Neutralization of Input in Parameter Description | MEDIUM | 5.1 | Oct 29, 2024 |
| CVE-2024-37389 | Apache NiFi: Improper Neutralization of Input in Parameter Context Description | MEDIUM | 5.3 | Jul 8, 2024 |
| CVE-2023-49145 | Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt | HIGH | 7.9 | Nov 27, 2023 |
| CVE-2023-40037 | Apache NiFi: Incomplete Validation of JDBC and JNDI Connection URLs | MEDIUM | 6.5 | Aug 18, 2023 |
| CVE-2023-36542 | Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources | HIGH | 8.7 | Jul 29, 2023 |
| CVE-2023-34212 | Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components | MEDIUM | 6.5 | Jun 12, 2023 |
| CVE-2023-34468 | Apache NiFi: Potential Code Injection with Database Services using H2 | HIGH | 8.8 | Jun 12, 2023 |
Showing 1 to 25 of 47 CVEs