Status: UPDATED
| Advisory ID: CVE-2026-70469
Key Details
| CVE | CVE-2026-70469 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-09-21 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | Apache NiFi and Apache Software Foundation Apache NiFi |
| Classified as | CWE-409 (Improper Handling of Highly Compressed Data (Data Amplification)) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject non-standard identifiers for gzip encoding, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.12.0 is the recommended mitigation, which disables decompression of gzip-encoded HTTP requests regardless of header number or encoding identifiers. (NVD)
What to Do
Monitor Apache's and Apache Software Foundation's web pages for any future patch releases. See vendor advisory link below.
References