Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache NiFi — Vulnerabilities & Security Advisories 55

All 55 CVE vulnerabilities found in Apache NiFi, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for Apache NiFi, an open-source data integration tool. It collects known security defects reported in Apache NiFi, covering advisories published within the most recent five years. The collection focuses on common weakness classes such as remote code execution, privilege escalation, and information disclosure. Readers can use this page to track the vendor's security advisories over time, understand recurring weakness patterns specific to this product line, and review the historical vulnerability landscape of Apache NiFi. All entries are verified against public CVE records and vendor announcements, ensuring the data remains current and accurate.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-70469 Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests CWE-409 - - 2026-09-16
CVE-2026-81866 Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration CWE-862 0.5 Low 2026-09-16
CVE-2026-82561 Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods CWE-862 5.9 Medium 2026-09-16
CVE-2026-86089 Apache NiFi: Missing Process Group Authorization for Connector Migration CWE-862 2.3 Low 2026-09-16
CVE-2026-68981 Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests CWE-409 8.8 High 2026-08-03
CVE-2026-68980 Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion CWE-863 2.3 Low 2026-08-03
CVE-2026-62354 Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests CWE-863 7.7 High 2026-08-03
CVE-2026-68979 Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates CWE-862 5.9 Medium 2026-08-03
CVE-2026-44914 Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents CWE-862 - - 2026-06-22
CVE-2026-44911 Apache NiFi: Incorrect Authorization for Configuration Verification Requests CWE-863 - - 2026-06-22
CVE-2026-44913 Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL CWE-116 - - 2026-06-22
CVE-2026-54665 Apache NiFi: Missing Validation for Proxy Host Headers CWE-346 - - 2026-06-22
CVE-2026-39816 Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService CWE-862 8.8AI High AI 2026-05-08
CVE-2026-25903 Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates CWE-862 6.5AI Medium AI 2026-02-17
CVE-2025-66524 Apache NiFi: Deserialization of Untrusted Data in GetAsanaObject Processor CWE-502 7.5AI High AI 2025-12-19
CVE-2025-27017 Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record CWE-538 6.5 - 2025-03-12
CVE-2024-56512 Apache NiFi: Missing Complete Authorization for Parameter and Service References CWE-638 6.5 - 2024-12-28
CVE-2024-52067 Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log CWE-532 4.9AI Medium AI 2024-11-21
CVE-2024-45477 Apache NiFi: Improper Neutralization of Input in Parameter Description CWE-79 4.6 Medium 2024-10-29
CVE-2024-37389 Apache NiFi: Improper Neutralization of Input in Parameter Context Description CWE-79 4.6 Medium 2024-07-08
CVE-2023-49145 Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt CWE-79 7.9 High 2023-11-27
CVE-2023-40037 Apache NiFi: Incomplete Validation of JDBC and JNDI Connection URLs CWE-184 8.1 - 2023-08-18
CVE-2023-36542 Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources CWE-94 8.8 - 2023-07-29
CVE-2023-34212 Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components CWE-502 8.8 - 2023-06-12
CVE-2023-34468 Apache NiFi: Potential Code Injection with Database Services using H2 CWE-94 8.8 - 2023-06-12
CVE-2023-22832 Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes CWE-611 7.5 - 2023-02-10
CVE-2022-33140 Improper Neutralization of Command Elements in Shell User Group Provider CWE-78 8.8 - 2022-06-15
CVE-2022-29265 Improper Restriction of XML External Entity References in Multiple Components CWE-611 7.5 - 2022-04-30
CVE-2022-26850 Insufficiently protected credentials 4.3 - 2022-04-06
CVE-2021-44145 Apache NiFi information disclosure by XXE 6.5 - 2021-12-17

All 55 known CVE vulnerabilities affecting Apache NiFi with full Chinese analysis, references, and POCs where available.