VendorsApachenifiall versions
Vulnerabilities

Apache Software Foundation NiFi

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

59CVEs
CVE-2017-12623
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Published 2017-10-10 · Modified
6.5EPSS 0.019
CVE-2021-44145
Apache NiFi information disclosure by XXE
Published 2021-12-17 · Modified
6.5EPSS 0.017
CVE-2026-82561
Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods
Published 2026-09-16 · Analyzed
6.5EPSS 0.005
CVE-2026-44911
Apache NiFi: Incorrect Authorization for Configuration Verification Requests
Published 2026-06-22 · Analyzed
6.3EPSS 0.005
CVE-2026-54665
Apache NiFi: Missing Validation for Proxy Host Headers
Published 2026-06-22 · Analyzed
6.3EPSS 0.003
CVE-2017-7665
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
Published 2017-06-12 · Modified
6.1EPSS 0.035
CVE-2020-1933
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.
Published 2020-01-28 · Modified
6.1EPSS 0.028
CVE-2018-17193
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Published 2018-12-19 · Modified
6.1EPSS 0.028
CVE-2020-13940
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).
Published 2020-10-01 · Modified
5.5EPSS 0.019
CVE-2024-37389
Apache NiFi: Improper Neutralization of Input in Parameter Context Description
Published 2024-07-08 · Modified
5.4EPSS 0.240
CVE-2024-56512
Apache NiFi: Missing Complete Authorization for Parameter and Service References
Published 2024-12-28 · Analyzed
5.4EPSS 0.031
CVE-2016-8748
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
Published 2017-10-19 · Modified
5.4EPSS 0.020
CVE-2020-27223
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
Published 2021-02-26 · Modified
5.3EPSS 0.780
CVE-2020-1928
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.
Published 2020-01-28 · Modified
5.3EPSS 0.040
CVE-2019-10083
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.
Published 2019-11-19 · Modified
5.3EPSS 0.028
CVE-2017-15703
Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack. The fix to properly handle Java deserialization was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
Published 2018-01-25 · Modified
5.0EPSS 0.009
CVE-2024-45477
Apache NiFi: Improper Neutralization of Input in Parameter Description
Published 2024-10-29 · Modified
4.6EPSS 0.007
CVE-2022-26850
Insufficiently protected credentials
Published 2022-04-06 · Modified
4.3EPSS 0.015
CVE-2026-81866
Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration
Published 2026-09-16 · Analyzed
4.3EPSS 0.006
← Prev2 / 2