PT-2026-93929 · Apache · Apache Nifi
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache NiFi version 2.11.0
Description
The application REST API fails to properly validate the
Content-Encoding header. The framework enforcement filter does not check for multiple instances of this header and accepts non-standard identifiers for gzip encoding. This allows a malicious client to send crafted requests that can lead to excessive memory consumption.Recommendations
Update Apache NiFi to version 2.12.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Nifi