// OSSeva Blog
SecurityApache NiFi Vulnerabilities by Version: CVEs for NiFi 1.x and 2.x
The short answer
Only NiFi 2.x gets security fixes. The latest release is 2.12.0, from 13 September 2026. NiFi 1.x reached end of support on 8 December 2024, and its final release was 1.28.1 on 19 November 2024. Since then the NiFi project has published twelve NiFi CVEs whose affected ranges include 1.x versions, plus one for NiFi Registry 1.x. Every fix shipped in a 2.x release, and none in 1.x.
NiFi release lines and support status
| Line | Status | Latest release |
|---|---|---|
| NiFi 2.x | Maintained | 2.12.0, 13 September 2026 |
| NiFi 1.x | End of support 8 December 2024 | 1.28.1, 19 November 2024 |
| NiFi Registry 2.x | Maintained, deprecated | 2.12.0, 13 September 2026 |
| NiFi Registry 1.x | End of support 8 December 2024 | 1.28.1 |
The NiFi download page calls 1.28 the last minor release of the version 1 series. It says the PMC may consider critical bug fixes for essential framework features on an exceptional basis, that those fixes do not include dependency upgrades, and that several core dependencies of NiFi 1 cannot be upgraded at all: Jetty 9.4, Spring Framework 5.3 and AngularJS 1.8. NiFi Registry was deprecated by a community vote in February 2026 and is planned for removal in NiFi 3.0. See the Apache NiFi end of life tracker for every release line.
NiFi CVEs since 1.x end of support
Each of these lists 1.x (or 0.x) versions in its affected range and has a fix in a single 2.x release. CVSS is NVD's own score where NVD has scored the record, otherwise the CISA-ADP score. The NiFi rating is the project's own, and the two often disagree: NiFi rates CVE-2026-68979 Medium while NVD scores it 9.8, and NiFi rates CVE-2026-62354 High while NVD scores it 4.3.
| CVE | Issue | CVSS | NiFi rating | Affected | Fixed in |
|---|---|---|---|---|---|
| CVE-2026-82561 | Missing authorization for components referenced in flow replacement and versioned flow updates | 6.5 (CISA-ADP) | Medium | 1.5.0 to 2.11.0 | 2.12.0 |
| CVE-2026-68981 | Memory exhaustion through gzip-encoded REST API requests | 7.5 (NVD) | High | 1.5.0 to 2.10.0 | 2.11.0 |
| CVE-2026-68979 | Missing authorization for components referenced by Parameter Context updates | 9.8 (NVD) | Medium | 1.10.0 to 2.10.0 | 2.11.0 |
| CVE-2026-62354 | Read-only users can run Parameter Context validation with their own values | 4.3 (NVD) | High | 1.10.0 to 2.10.0 | 2.11.0 |
| CVE-2026-44914 | Restricted component permissions not checked when replacing Process Groups | 7.2 (NVD) | High | 1.12.0 to 2.9.0 | 2.10.0 |
| CVE-2026-44913 | SQL injection through table names in CaptureChangeMySQL | 7.2 (NVD) | Medium | 1.2.0 to 2.9.0 | 2.10.0 |
| CVE-2026-54665 | X-ProxyHost and X-Forwarded-Host headers not validated | 5.3 (NVD) | Medium | 0.0.1 to 2.9.0 | 2.10.0 |
| CVE-2026-44911 | Read-only users can run configuration verification with their own properties | 6.3 (NVD) | Low | 1.15.0 to 2.9.0 | 2.10.0 |
| CVE-2026-25903 | Restricted component permissions not checked on property updates | 6.6 (NVD) | High | 1.1.0 to 2.7.2 | 2.8.0 |
| CVE-2025-66524 | Deserialization of untrusted data in the GetAsanaObject processor | 8.8 (NVD) | High | 1.20.0 to 2.6.0 | 2.7.0 |
| CVE-2025-27017 | MongoDB username and password written to provenance events | 6.5 (NVD) | Medium | 1.13.0 to 2.2.0 | 2.3.0 |
| CVE-2024-56512 | Incomplete authorization for Parameter Context and service references when creating Process Groups | 5.4 (NVD) | Low | 1.10.0 to 2.0.0 | 2.1.0 |
| CVE-2026-87976 | NiFi Registry: crafted NAR coordinates write outside the extension bundle store | 8.1 (NVD) | High | Registry 0.4.0 to 2.11.0 | Registry 2.12.0 |
Most of these are authorization gaps that only matter where NiFi uses fine-grained, component-level policies. A deployment where every user has full write access is not exposed to them, because write access is already the security boundary there. The ones that do not depend on policy design are CVE-2026-68981, which a client can use to exhaust memory, CVE-2026-54665 on the proxy headers, CVE-2026-44913 for flows that use CaptureChangeMySQL, CVE-2025-66524 for flows that use GetAsanaObject, and CVE-2025-27017, which leaks MongoDB credentials to anyone who can read provenance.
NiFi 2.x
NiFi 2 needs Java 21. Each advisory names one fixed version, the next 2.x release, so staying on an older 2.x release means running without every fix since. Three 2.x CVEs do not reach 1.x: CVE-2026-39816 (8.8, missing Execute Code permission on TinkerpopClientService, fixed in 2.9.0), CVE-2026-68980 (9.1, authorization bypass for Parameter Context asset deletion, fixed in 2.11.0) and CVE-2026-70469 (7.5, a bypass of the 2.11.0 gzip block, fixed in 2.12.0). On 2.11.0, the CVE-2026-68981 fix is itself incomplete until 2.12.0.
NiFi 1.x
NiFi 1.28.1 fixed CVE-2024-52067 (4.9), which wrote sensitive parameter values to the debug log, and it is the last 1.x release with any fix. Earlier 1.x releases fixed CVE-2023-49145 in 1.24.0, CVE-2023-36542 (8.8) in 1.23.0 and CVE-2023-34468 (8.8) in 1.22.0, so a cluster still on 1.19 or 1.21 is missing those as well as the thirteen in the table. NiFi's migration guidance requires 1.27.0 or later before moving to 2.0, and 2.x removes the variable registry, flow.xml.gz and a long list of components, so the move takes planning. See Apache NiFi 1.x end of life and the NiFi 1.x to 2.0 upgrade guide.
Clustered NiFi 1.x also depends on ZooKeeper for coordinator election, often on an ensemble as old as the cluster. See ZooKeeper for NiFi.
What to do on each line
- 2.x. Upgrade to 2.12.0. Fixes land only in new 2.x releases.
- 1.x. Get to 1.28.1 if you are not there, then either migrate to 2.x or take patched builds from a supplier that backports fixes. Meanwhile, keep the REST API off untrusted networks, check who holds read access to provenance and Parameter Contexts, and validate proxy headers at the reverse proxy in front of NiFi.
- NiFi Registry. Upgrade to Registry 2.12.0 for CVE-2026-87976, and plan the move to a Git-based flow registry client, since Registry is deprecated.
Where OSSeva fits
OSSeva backports NiFi security fixes across the 1.x line, including the Jetty, Jackson and Netty dependencies bundled in NiFi's NARs, with flow.xml.gz, NARs and parameter contexts unchanged. Builds ship as Docker images and tarballs, and are available now on the Patch, Assure and Operate tiers. Assure adds a processor and controller service inventory mapped against what 2.x removed and a costed flow migration plan, and Operate adds 24/7 dataflow monitoring with a 15-minute P1 response, named NiFi engineers and migration execution to 2.x. See Apache NiFi extended support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.