VulnSea

nifi vulnerabilities

CVEs whose affected-version data names the nifi package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-87976High· 8.1
6d ago

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coord…

Twilightapache · nifiEPSS 0.39%via NVD
CVE-2026-86089High· 7.1⚖ disputed
6d ago

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods ag…

Twilightapache · nifiEPSS 0.29%via NVD
CVE-2026-81866Medium· 4.3⚖ disputed
6d ago

Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration

Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Conn…

Sunlitapache · nifiEPSS 0.40%via NVD
CVE-2026-82561Medium· 6.5
6d ago

Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase…

Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase…

Sunlitapache · nifiEPSS 0.26%via NVD
CVE-2026-70469High· 7.5
6d ago

Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding

Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not c…

Twilightapache · nifiEPSS 0.37%via NVD
CVE-2026-44914High· 7.2
3mo ago

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additio…

Twilightapache · nifiEPSS 0.66%via NVD
CVE-2021-20190High· 8.1
5y ago

A flaw was found in jackson-databind before 2.9.10.7

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system av…

Twilightfasterxml · jackson-databindEPSS 7.5%via NVD
CVE-2019-10086High· 7.3
7y ago

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using…

Twilightapache · commons_beanutilsEPSS 29%via NVD
nifi vulnerabilities (CVEs) · VulnSea