← All Advisories

CVE-2026-70469

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-70469

Key Details

CVECVE-2026-70469
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsApache NiFi and Apache Software Foundation Apache NiFi
Classified asCWE-409 (Improper Handling of Highly Compressed Data (Data Amplification))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
ApacheNiFi
Apache Software FoundationApache NiFi
SubsystemsGeneral OT
SectorsMultiple

What to Know

Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject non-standard identifiers for gzip encoding, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.12.0 is the recommended mitigation, which disables decompression of gzip-encoded HTTP requests regardless of header number or encoding identifiers. (NVD)

What to Do

Monitor Apache's and Apache Software Foundation's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-70469
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-70469
Vendor advisoryhttps://lists.apache.org/thread/mjpv7r4djgn7fdvhnpjwgr2rcto47mx0