ThreatCluster

Apache NiFi Vulnerabilities Lead to Authorization Bypass and Memory Issues

First seen 4 Aug 2026, 12:18 UTC GbhackersCybersecuritynews 86% similarity 69

Article Content

Browse articles
ThreatCluster

Apache NiFi has disclosed four critical vulnerabilities affecting its Web API and Parameter Context authorization controls. Users are urged to upgrade to version 2.11.0 to mitigate risks of authorization bypass, unauthorized configuration changes, and memory exhaustion. The vulnerabilities allow attackers to exploit the system via specially crafted gzip-compressed HTTP requests, leading to potential unauthorized deletion of assets and code execution in specific deployments. Affected versions range from 1.5.0 to 2.10.0. The vulnerabilities have been classified with high severity due to their potential impact on system integrity and availability. Users are advised to take immediate action to secure their installations.

Key Points: • Four critical vulnerabilities disclosed in Apache NiFi's Web API. • Affected versions include 1.5.0 through 2.10.0; upgrade to 2.11.0 is recommended. • Exploitation could lead to unauthorized access and memory exhaustion.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
Apache NiFi vulnerabilities disclosed
Four vulnerabilities affecting authorization controls and memory management were announced, prompting an upgrade to version 2.11.0.
Cybersecuritynews
2026-08-04
Security advisories issued
Apache NiFi issued advisories detailing the vulnerabilities and their potential impacts, urging users to upgrade.
Gbhackers

Community

Browse all →