PT-2026-93929 · Apache · Apache Nifi

·

CVE-2026-70469

·

Published

2026-09-16

·

Updated

2026-10-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache NiFi version 2.11.0
Description The application REST API fails to properly validate the Content-Encoding header. The framework enforcement filter does not check for multiple instances of this header and accepts non-standard identifiers for gzip encoding. This allows a malicious client to send crafted requests that can lead to excessive memory consumption.
Recommendations Update Apache NiFi to version 2.12.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NIFI-2026-70469
CVE-2026-70469

Affected Products

Apache Nifi