Known Vulnerabilities for Apache NiFi by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache NiFi" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-87976 json | Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group,... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-86089 json | Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API meth... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-82561 json | Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-81866 json | Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-70469 json | Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that in... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-68981 json | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filt... | Not Provided | 2026-08-03 | 2026-08-04 |
| CVE-2026-68980 json | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through th... | Not Provided | 2026-08-03 | 2026-08-04 |
| CVE-2026-68979 json | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization chec... | Not Provided | 2026-08-03 | 2026-08-05 |
| CVE-2026-62354 json | Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with rea... | Not Provided | 2026-08-03 | 2026-08-05 |
| CVE-2026-54665 json | Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alte... | Not Provided | 2026-06-22 | 2026-06-22 |