// OSSeva Blog
OperationsWho Provides Extended Support for Apache NiFi 1.x After NiFi 2.0?
The short answer
Two providers publish ongoing security fixes for NiFi 1.x. Cloudera supports Cloudera Flow Management 2.1.7, which ships its own NiFi 1.28.1 builds, until September 2027, for customers running Cloudera's distribution. OSSeva ships patched builds of Apache NiFi 1.19, 1.23, 1.26 and 1.28, including the bundled Jetty and Spring libraries the NiFi project says it cannot upgrade on 1.x. Perforce OpenLogic sells NiFi support without patched builds.
If you run Apache's own NiFi 1.x binaries, Cloudera's support does not reach them unless you move to its distribution. That is the main question to settle before comparing anything else.
Where Apache NiFi 1.x stands
The NiFi download page states that 1.28 is the last minor release of the 1.x series, with an end of support date of 8 December 2024. The project may consider critical framework fixes "on an exceptional basis", but those fixes do not include dependency upgrades, and the page names Jetty 9.4, Spring Framework 5.3 and AngularJS 1.8 as dependencies that cannot be upgraded on 1.x.
| Line | Status on 6 October 2026 | Latest release |
|---|---|---|
| NiFi 2.x | Current, all development | 2.12.0 (13 September 2026) |
| NiFi 1.28 | End of support since 8 December 2024 | 1.28.1, the final 1.x release |
| NiFi 1.27 and earlier | End of life | No further releases |
NiFi 2 needs Java 21, replaces flow.xml.gz with flow.json.gz and removes a long list of deprecated components, and an upgrade must pass through 1.27 first. The NiFi end-of-life chart tracks every line, and NiFi vulnerabilities by version shows what reaches 1.x.
Apache NiFi support providers compared
Each row reflects what the provider publishes on its own site as of 6 October 2026.
| Provider | What it covers | NiFi versions | Delivery model | Self-managed? |
|---|---|---|---|---|
| Cloudera Flow Management (on premises) | Cloudera's own NiFi distribution with support and service packs | CFM 2.1.7 (NiFi 1.26 to 1.28.1 builds) to September 2027; CFM 4.10 to 4.12 (NiFi 2.3 to 2.6 builds) to May 2028, October 2028 and March 2029 | Cloudera subscription and Cloudera builds | Yes, on Cloudera's distribution |
| Cloudera Data Flow (cloud) | Managed NiFi runtimes, each supported for 18 months | NiFi 1.28.1 runtimes to September 2027; the 1.27.0 runtime ended in April 2026 | Cloudera managed service | No |
| OSSeva | Backported fixes for NiFi's own code and the libraries bundled in its NARs, such as Jetty, Jackson, Netty and Spring Framework 5.3; processor inventory and migration planning on higher tiers | Apache NiFi 1.19, 1.23, 1.26 and 1.28; covers Apache or Cloudera-packaged binaries at the exact version run | Signed Docker images and tarballs | Yes |
| Perforce OpenLogic | Technical support for NiFi at Gold, Silver and Bronze levels; NiFi is not on its patched long-term support list | No version list published | Support subscription | Yes |
| Snowflake Openflow | A managed integration service built on Apache NiFi, deployed in your AWS VPC or in Snowpark Container Services | Not a support offer for existing NiFi clusters | Snowflake service | No |
Cloudera's dates are the longest published for NiFi 1.x, and they cover Cloudera's builds, not Apache's. Openflow is in the table because Snowflake acquired Datavolo, a company built around Apache NiFi, and the question of whether Datavolo still sells NiFi support comes up often. Datavolo's site now carries the acquisition notice, and Snowflake's NiFi-based product is Openflow, a destination for flows rather than support for the clusters you run today.
How the providers differ
Cloudera
Cloudera is the clear choice if you already run Cloudera Flow Management or can move to it. Its 2.1.7 service packs ship Cloudera builds of NiFi 1.28.1, supported until September 2027, and its 4.x releases give a supported NiFi 2 path into 2029. Earlier CFM 2.1.5 and 2.1.6 releases ended in August 2025. In the cloud, Cloudera Data Flow supports each NiFi runtime for 18 months, so its 1.28.1 runtimes also end in September 2027. If your NiFi sits next to older CDH or HDP clusters, CDH and HDP end of life covers that side.
Perforce OpenLogic
OpenLogic lists NiFi among more than 400 supported technologies at all three support levels. It suits a team that wants one contract for help running NiFi alongside the rest of its stack. It does not publish patched NiFi 1.x builds. See OSSeva vs OpenLogic.
OSSeva
OSSeva for Apache NiFi patches the 1.x line in place, so flow.xml.gz, the NAR set, parameter contexts and controller services stay as configured. That covers NiFi's own authentication and authorisation code and the libraries inside the NARs, where most NiFi advisories land. OSSeva matches the exact binaries you run, whether Apache's or Cloudera-packaged. Assure adds a processor and controller service inventory, a gap analysis against what NiFi 2 removed, a credential handling audit and a costed migration plan; Operate adds 24/7 backpressure and throughput monitoring, a 15-minute P1 response and execution of the flow migration. Pricing is per cluster, not per flow or data volume.
How to choose
| Situation | Usual answer |
|---|---|
| Already on Cloudera Flow Management 2.1.7 | Stay on Cloudera's service packs to September 2027 and plan CFM 4.x |
| Apache NiFi 1.x binaries, flows that use removed processors | OSSeva patched builds while the processor gap is closed on 1.27 or 1.28 |
| Apache NiFi 1.x, flows already clean of deprecated components | Upgrade to 1.27 or 1.28, then to 2.x |
| Want NiFi off your infrastructure and already on Snowflake | Evaluate Openflow as a migration target |
| Need operational help more than patches | OpenLogic, or OSSeva Operate |
Our NiFi 1.x to 2.0 upgrade guide covers the sequence and the inventory step, and NiFi 1.x end-of-life dataflows covers running extended support during the move.
Where OSSeva fits
OSSeva covers Apache NiFi 1.x for estates that are not on Cloudera's distribution, or that are behind Cloudera's own lines, with signed builds and a migration plan built from a real processor inventory. See the extended support vendor roundup for how OSSeva compares across other technologies.
Frequently asked questions
Who provides extended support for Apache NiFi 1.x?
Cloudera supports its own NiFi 1.28.1 builds in Cloudera Flow Management 2.1.7 and Cloudera Data Flow until September 2027. OSSeva ships patched Apache NiFi 1.19, 1.23, 1.26 and 1.28 builds. OpenLogic offers general NiFi support without patched 1.x builds.
Is Apache NiFi 1.x still supported?
Not by Apache. The download page gives 1.28's end of support as 8 December 2024, and 1.28.1 was the last release. The project may make exceptional critical fixes, but says those will not include dependency upgrades.
Does Cloudera support Apache NiFi 1.x?
Cloudera supports its own NiFi distribution. CFM 2.1.7, based on NiFi 1.28.1 in its latest service packs, is supported until September 2027. Apache binaries outside that distribution are not covered.
What happened to Datavolo NiFi support?
Snowflake acquired Datavolo, and Datavolo's site now carries that announcement. Snowflake's NiFi-based product is Openflow, a managed integration service. It does not publish a support offer for self-managed NiFi 1.x clusters.
Can we upgrade straight from NiFi 1.x to 2.0?
Only from 1.27.0 or later, per NiFi's migration guidance. Clusters on 1.19 or 1.23 move to 1.27 or 1.28 first, replace removed components there, and then move to 2.x on Java 21.
Tags
Related articles
Apache Storm Vulnerabilities by Version: CVEs for Storm 1.2, 2.x and 3.x
October 6, 2026Securityetcd Vulnerabilities by Version: CVEs for etcd 3.3, 3.4, 3.5, 3.6 and 3.7
October 6, 2026SecurityClickHouse Vulnerabilities by Version: CVEs for ClickHouse 22.x to 26.x, LTS and Stable
October 6, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.