apache-nifi

Direct Vulnerabilities

Known vulnerabilities in the apache-nifi package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Resource Exhaustion

<2.11.0-r0
  • L
HTTP Request Smuggling

<2.11.0-r0
  • L
Resource Exhaustion

<2.11.0-r0
  • L
CVE-2026-59949

<2.11.0-r0
  • L
CRLF Injection

<2.11.0-r0
  • L
Improper Access Control

<2.11.0-r0
  • L
GHSA-mfg7-5gfp-c4w3

<2.11.0-r0
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.11.0-r0
  • L
HTTP Request Smuggling

<2.11.0-r0
  • L
Resource Exhaustion

<2.11.0-r0
  • H
Resource Exhaustion

<2.11.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<2.11.0-r0
  • L
CVE-2026-41695

<2.10.0-r0
  • H
CVE-2026-41848

<2.10.0-r0
  • L
CVE-2026-41850

<2.10.0-r0
  • M
CVE-2026-41852

<2.10.0-r0
  • H
CVE-2026-41851

<2.10.0-r0
  • L
Use of Non-Canonical URL Paths for Authorization Decisions

<2.10.0-r0
  • L
Improper Handling of Alternate Encoding

<2.10.0-r0
  • L
Information Exposure

<2.10.0-r0
  • L
Improper Input Validation

<2.10.0-r0
  • L
CVE-2026-10532

<2.10.0-r0
  • L
Deserialization of Untrusted Data

<2.10.0-r0
  • L
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<2.10.0-r0
  • L
CVE-2026-9828

<2.10.0-r0
  • L
Incomplete Blacklist

<2.10.0-r0
  • L
Incomplete Blacklist

*
  • L
CVE-2025-14813

<2.10.0-r0
  • L
CVE-2026-54665

<2.10.0-r0
  • L
CVE-2026-44913

<2.10.0-r0
  • L
CVE-2026-44914

<2.10.0-r0
  • L
CVE-2026-44911

<2.10.0-r0
  • M
Allocation of Resources Without Limits or Throttling

<2.10.0-r0
  • L
HTTP Request Smuggling

<2.10.0-r0
  • H
Resource Exhaustion

<2.10.0-r0
  • L
Information Exposure

<2.10.0-r0
  • L
Improper Verification of Cryptographic Signature

<2.10.0-r0
  • C
Insufficient Verification of Data Authenticity

<2.10.0-r0
  • L
Improper Verification of Source of a Communication Channel

<2.10.0-r0
  • L
Use of Insufficiently Random Values

<2.10.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<2.10.0-r0
  • L
Information Exposure

<2.10.0-r0
  • L
Resource Exhaustion

<2.10.0-r0
  • L
Improper Access Control

<2.10.0-r0
  • C
Insufficient Verification of Data Authenticity

<2.10.0-r0
  • C
Improper Authentication

<2.10.0-r0
  • L
Uncontrolled Recursion

<2.10.0-r0
  • L
GHSA-72hv-8253-57qq

<2.9.0-r0
  • L
Deserialization of Untrusted Data

<2.10.0-r0
  • L
Resource Exhaustion

<2.10.0-r0
  • L
Deserialization of Untrusted Data

<2.10.0-r0
  • L
Deserialization of Untrusted Data

<2.10.0-r0
  • L
Deserialization of Untrusted Data

<2.10.0-r0
  • H
HTTP Request Smuggling

<2.10.0-r0
  • L
Integer Overflow or Wraparound

<2.10.0-r0
  • C
Improper Input Validation

<2.10.0-r0
  • L
Missing Release of Resource after Effective Lifetime

<2.10.0-r0
  • C
HTTP Request Smuggling

<2.10.0-r0
  • L
Resource Exhaustion

<2.10.0-r0
  • C
HTTP Request Smuggling

<2.10.0-r0
  • H
HTTP Response Splitting

<2.10.0-r0
  • L
CRLF Injection

<2.10.0-r0
  • H
Missing Authorization

<2.9.0-r0
  • L
CVE-2026-22754

<2.10.0-r0
  • L
CVE-2026-22753

<2.10.0-r0
  • L
CVE-2026-22746

<2.10.0-r0
  • M
CVE-2026-22748

<2.10.0-r0
  • H
CVE-2026-22747

<2.10.0-r0
  • L
Missing Critical Step in Authentication

<2.10.0-r0
  • L
CVE-2026-3505

<2.10.0-r0
  • H
Out-of-bounds Read

<2.10.0-r0
  • L
CVE-2026-0636

<2.10.0-r0
  • L
CVE-2026-5588

<2.10.0-r0
  • L
CVE-2026-22751

<2.10.0-r0
  • L
CVE-2026-5598

<2.10.0-r0
  • L
Improper Validation of Specified Index, Position, or Offset in Input

<2.9.0-r0
  • C
HTTP Request Smuggling

<2.9.0-r0
  • L
Race Condition

<2.9.0-r0
  • L
GHSA-2m67-wjpj-xhg9

<2.9.0-r0
  • H
Improper Certificate Validation

<2.9.0-r0
  • H
Information Exposure Through Log Files

<2.9.0-r0
  • H
Allocation of Resources Without Limits or Throttling

<2.9.0-r0
  • L
CVE-2026-22732

<2.9.0-r0