Apache NiFi
Apache Software Foundation- Product type
- Other
- Catalog vulnerabilities
- 47
Severity across 8 analyzed records
en
Severity across 8 analyzed records
Verify to analyze this security profile
As of 09/20/2026, within CyStack's analyzed data, Apache NiFi has 8 security vulnerabilities published in the last 90 days. Of these, 3 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Apache NiFi and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-70469Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests | Exploitation statusNot known exploited | FixNot confirmed | Published09/16/2026 | SeverityHigh |
CVE-2026-81866Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration | Exploitation statusNot known exploited | FixYes | Published09/16/2026 | SeverityLow |
CVE-2026-82561Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods | Exploitation statusNot known exploited | FixYes | Published09/16/2026 | SeverityMedium |
CVE-2026-86089Apache NiFi: Missing Process Group Authorization for Connector Migration | Exploitation statusNot known exploited | FixNot confirmed | Published09/16/2026 | SeverityLow |
CVE-2026-68981Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityHigh |
CVE-2026-68980Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityLow |
CVE-2026-62354Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityHigh |
CVE-2026-68979Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityMedium |
CVE-2026-44914Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents | Exploitation statusNot known exploited | FixYes | Published06/22/2026 | SeverityHigh |
CVE-2026-44911Apache NiFi: Incorrect Authorization for Configuration Verification Requests | Exploitation statusNot known exploited | FixYes | Published06/22/2026 | SeverityLow |
CVE-2026-44913Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL | Exploitation statusNot known exploited | FixYes | Published06/22/2026 | SeverityMedium |
CVE-2026-54665Apache NiFi: Missing Validation for Proxy Host Headers | Exploitation statusNot known exploited | FixYes | Published06/22/2026 | SeverityMedium |
CVE-2026-39816Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService | Exploitation statusNot known exploited | FixYes | Published05/08/2026 | SeverityHigh |
CVE-2026-25903Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates | Exploitation statusNot known exploited | FixYes | Published02/17/2026 | SeverityHigh |
CVE-2025-66524Apache NiFi: Deserialization of Untrusted Data in GetAsanaObject Processor | Exploitation statusNot known exploited | FixYes | Published12/19/2025 | SeverityHigh |
CVE-2025-27017Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record | Exploitation statusNot known exploited | FixYes | Published03/12/2025 | SeverityMedium |
CVE-2024-56512Apache NiFi: Missing Complete Authorization for Parameter and Service References | Exploitation statusNot known exploited | FixYes | Published12/28/2024 | SeverityLow |
CVE-2024-52067Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log | Exploitation statusNot known exploited | FixYes | Published11/21/2024 | SeverityMedium |
CVE-2024-45477Apache NiFi: Improper Neutralization of Input in Parameter Description | Exploitation statusNot known exploited | FixYes | Published10/29/2024 | SeverityMedium |
CVE-2024-37389Apache NiFi: Improper Neutralization of Input in Parameter Context Description | Exploitation statusNot known exploited | FixYes | Published07/08/2024 | SeverityMedium |
CVE-2023-49145Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt | Exploitation statusNot confirmed | FixYes | Published11/27/2023 | SeverityHigh |
CVE-2023-40037Apache NiFi: Incomplete Validation of JDBC and JNDI Connection URLs | Exploitation statusNot known exploited | FixYes | Published08/18/2023 | SeverityUnknown |
CVE-2023-36542Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources | Exploitation statusNot known exploited | FixYes | Published07/29/2023 | SeverityHigh |
CVE-2023-34212Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components | Exploitation statusNot known exploited | FixYes | Published06/12/2023 | SeverityUnknown |
CVE-2023-34468Apache NiFi: Potential Code Injection with Database Services using H2 | Exploitation statusNot known exploited | FixYes | Published06/12/2023 | SeverityHigh |
CVE-2023-22832Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes | Exploitation statusNot known exploited | FixYes | Published02/10/2023 | SeverityHigh |
CVE-2022-33140Improper Neutralization of Command Elements in Shell User Group Provider | Exploitation statusNot confirmed | FixYes | Published06/15/2022 | SeverityUnknown |
CVE-2022-29265Improper Restriction of XML External Entity References in Multiple Components | Exploitation statusNot confirmed | FixNot confirmed | Published04/30/2022 | SeverityUnknown |
CVE-2022-26850Insufficiently protected credentials | Exploitation statusNot confirmed | FixNot confirmed | Published04/06/2022 | SeverityUnknown |
CVE-2021-44145Apache NiFi information disclosure by XXE | Exploitation statusNot confirmed | FixNot confirmed | Published12/17/2021 | SeverityUnknown |
CVE-2020-1933 | Exploitation statusNot confirmed | FixNot confirmed | Published01/28/2020 | SeverityUnknown |
CVE-2020-1928 | Exploitation statusNot confirmed | FixNot confirmed | Published01/28/2020 | SeverityUnknown |
CVE-2018-17192 | Exploitation statusNot confirmed | FixNot confirmed | Published12/19/2018 | SeverityUnknown |
CVE-2018-17193 | Exploitation statusNot confirmed | FixNot confirmed | Published12/19/2018 | SeverityUnknown |
CVE-2018-17195 | Exploitation statusNot confirmed | FixNot confirmed | Published12/19/2018 | SeverityUnknown |
CVE-2018-17194 | Exploitation statusNot confirmed | FixNot confirmed | Published12/19/2018 | SeverityUnknown |
CVE-2018-1310 | Exploitation statusNot confirmed | FixNot confirmed | Published05/23/2018 | SeverityUnknown |
CVE-2018-1309 | Exploitation statusNot confirmed | FixNot confirmed | Published05/23/2018 | SeverityUnknown |
CVE-2017-15703 | Exploitation statusNot confirmed | FixNot confirmed | Published01/25/2018 | SeverityUnknown |
CVE-2017-15697 | Exploitation statusNot confirmed | FixNot confirmed | Published01/23/2018 | SeverityUnknown |
CVE-2017-12632 | Exploitation statusNot confirmed | FixNot confirmed | Published01/23/2018 | SeverityUnknown |
CVE-2016-8748 | Exploitation statusNot confirmed | FixNot confirmed | Published10/19/2017 | SeverityUnknown |
CVE-2017-5636 | Exploitation statusNot confirmed | FixNot confirmed | Published10/19/2017 | SeverityUnknown |
CVE-2017-5635 | Exploitation statusNot confirmed | FixNot confirmed | Published10/19/2017 | SeverityUnknown |
CVE-2017-12623 | Exploitation statusNot confirmed | FixNot confirmed | Published10/10/2017 | SeverityUnknown |
CVE-2017-7667 | Exploitation statusNot confirmed | FixNot confirmed | Published06/12/2017 | SeverityUnknown |
CVE-2017-7665 | Exploitation statusNot confirmed | FixNot confirmed | Published06/12/2017 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan