Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache NiFi | 1.5.0≤ 2.11.0 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache NiFi | 1.5.0 ~ 2.11.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87976 | 7.2 HIGH | Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles |
| CVE-2026-86089 | 2.3 LOW | Apache NiFi: Missing Process Group Authorization for Connector Migration |
| CVE-2026-81866 | 0.5 LOW | Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configur |
| CVE-2026-86465 | Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via us | |
| CVE-2026-70469 | Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests | |
| CVE-2026-82311 | Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _us | |
| CVE-2026-86462 | Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed | |
| CVE-2026-86792 | Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Sched | |
| CVE-2026-82310 | Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API | |
| CVE-2026-76186 | Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session iden | |
| CVE-2026-76187 | Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session J | |
| CVE-2026-86466 | Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validate | |
| CVE-2026-59739 | Apache ZooKeeper: Information disclosure via SetWatches reconnect replay | |
| CVE-2026-59969 | Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode | |
| CVE-2026-79993 | Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion | |
| CVE-2026-84439 | Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources | |
| CVE-2026-84501 | Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationP | |
| CVE-2026-68536 | Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability | |
| CVE-2026-76646 | Apache MyFaces: Denial of Service via Unbounded Request Parsing |
No comments yet