Known Vulnerabilities for Nifi by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Nifi" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68981 json | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filt... | Not Provided | 2026-08-03 | 2026-08-04 |
| CVE-2026-68980 json | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through th... | Not Provided | 2026-08-03 | 2026-08-04 |
| CVE-2026-68979 json | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization chec... | Not Provided | 2026-08-03 | 2026-08-05 |
| CVE-2026-62354 json | Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with rea... | Not Provided | 2026-08-03 | 2026-08-05 |
| CVE-2026-54665 json | Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alte... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-44914 json | Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components wi... | Not Provided | 2026-06-22 | 2026-06-24 |
| CVE-2026-44913 json | Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 a... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-44911 json | Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients w... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-39816 json | Not Provided | 2026-05-08 | 2026-05-09 | |
| CVE-2026-25903 json | Not Provided | 2026-02-17 | 2026-03-30 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Nifi | 1.9.2 | |||
| Application | Apache | Nifi | 1.9.2 | |||
| Application | Apache | Nifi | 1.9.2 | |||
| Application | Apache | Nifi | 1.9.2 | |||
| Application | Apache | Nifi | 1.9.1 | |||
| Application | Apache | Nifi | 1.9.1 | |||
| Application | Apache | Nifi | 1.9.0 | |||
| Application | Apache | Nifi | 1.9.0 | |||
| Application | Apache | Nifi | 1.9.0 | |||
| Application | Apache | Nifi | 1.8.0 | |||
| Application | Apache | Nifi | 1.8.0 | |||
| Application | Apache | Nifi | 1.8.0 | |||
| Application | Apache | Nifi | 1.8.0 | |||
| Application | Apache | Nifi | 1.8.0 | |||
| Application | Apache | Nifi | 1.7.1 | |||
| Application | Apache | Nifi | 1.7.1 | |||
| Application | Apache | Nifi | 1.7.1 | |||
| Application | Apache | Nifi | 1.7.0 | |||
| Application | Apache | Nifi | 1.7.0 | |||
| Application | Apache | Nifi | 1.7.0 |