Apache / Nifi
54 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-68981 | Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests | HIGH | 8.8 | Aug 3, 2026 |
| CVE-2026-68980 | Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion | LOW | 2.3 | Aug 3, 2026 |
| CVE-2026-62354 | Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests | HIGH | 7.7 | Aug 3, 2026 |
| CVE-2026-68979 | Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates | MEDIUM | 5.9 | Aug 3, 2026 |
| CVE-2026-44914 | Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents | HIGH | 7.5 | Jun 22, 2026 |
| CVE-2026-44911 | Apache NiFi: Incorrect Authorization for Configuration Verification Requests | LOW | 2.3 | Jun 22, 2026 |
| CVE-2026-44913 | Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL | MEDIUM | 5.2 | Jun 22, 2026 |
| CVE-2026-54665 | Apache NiFi: Missing Validation for Proxy Host Headers | MEDIUM | 6.3 | Jun 22, 2026 |
| CVE-2026-39816 | Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService | HIGH | 7.5 | May 8, 2026 |
| CVE-2026-25903 | Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates | HIGH | 8.7 | Feb 17, 2026 |
| CVE-2025-66524 | Apache NiFi: Deserialization of Untrusted Data in GetAsanaObject Processor | HIGH | 7.5 | Dec 19, 2025 |
| CVE-2025-27017 | Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record | MEDIUM | 6.9 | Mar 12, 2025 |
| CVE-2024-56512 | Apache NiFi: Missing Complete Authorization for Parameter and Service References | LOW | 2.1 | Dec 28, 2024 |
| CVE-2024-52067 | Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log | MEDIUM | 6.9 | Nov 21, 2024 |
| CVE-2024-45477 | Apache NiFi: Improper Neutralization of Input in Parameter Description | MEDIUM | 5.1 | Oct 29, 2024 |
| CVE-2024-37389 | Apache NiFi: Improper Neutralization of Input in Parameter Context Description | MEDIUM | 5.3 | Jul 8, 2024 |
| CVE-2023-49145 | Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt | HIGH | 7.9 | Nov 27, 2023 |
| CVE-2023-40037 | Apache NiFi: Incomplete Validation of JDBC and JNDI Connection URLs | MEDIUM | 6.5 | Aug 18, 2023 |
| CVE-2023-36542 | Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources | HIGH | 8.7 | Jul 29, 2023 |
| CVE-2023-34212 | Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components | MEDIUM | 6.5 | Jun 12, 2023 |
| CVE-2023-34468 | Apache NiFi: Potential Code Injection with Database Services using H2 | HIGH | 8.8 | Jun 12, 2023 |
| CVE-2023-22832 | Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes | HIGH | 7.5 | Feb 10, 2023 |
| CVE-2022-33140 | Improper Neutralization of Command Elements in Shell User Group Provider | HIGH | 8.8 | Jun 15, 2022 |
| CVE-2022-29265 | Improper Restriction of XML External Entity References in Multiple Components | HIGH | 7.5 | Apr 30, 2022 |
| CVE-2022-26850 | Insufficiently protected credentials | MEDIUM | 6.5 | Apr 6, 2022 |
Showing 1 to 25 of 54 CVEs