Back to blog

// OSSeva Blog

Security

Apache NiFi Vulnerabilities by Version: CVEs for NiFi 1.x and 2.x

Randall McClure8 min read

The short answer

Only NiFi 2.x gets security fixes. The latest release is 2.12.0, from 13 September 2026. NiFi 1.x reached end of support on 8 December 2024, and its final release was 1.28.1 on 19 November 2024. Since then the NiFi project has published twelve NiFi CVEs whose affected ranges include 1.x versions, plus one for NiFi Registry 1.x. Every fix shipped in a 2.x release, and none in 1.x.

NiFi release lines and support status

LineStatusLatest release
NiFi 2.xMaintained2.12.0, 13 September 2026
NiFi 1.xEnd of support 8 December 20241.28.1, 19 November 2024
NiFi Registry 2.xMaintained, deprecated2.12.0, 13 September 2026
NiFi Registry 1.xEnd of support 8 December 20241.28.1

The NiFi download page calls 1.28 the last minor release of the version 1 series. It says the PMC may consider critical bug fixes for essential framework features on an exceptional basis, that those fixes do not include dependency upgrades, and that several core dependencies of NiFi 1 cannot be upgraded at all: Jetty 9.4, Spring Framework 5.3 and AngularJS 1.8. NiFi Registry was deprecated by a community vote in February 2026 and is planned for removal in NiFi 3.0. See the Apache NiFi end of life tracker for every release line.

NiFi CVEs since 1.x end of support

Each of these lists 1.x (or 0.x) versions in its affected range and has a fix in a single 2.x release. CVSS is NVD's own score where NVD has scored the record, otherwise the CISA-ADP score. The NiFi rating is the project's own, and the two often disagree: NiFi rates CVE-2026-68979 Medium while NVD scores it 9.8, and NiFi rates CVE-2026-62354 High while NVD scores it 4.3.

CVEIssueCVSSNiFi ratingAffectedFixed in
CVE-2026-82561Missing authorization for components referenced in flow replacement and versioned flow updates6.5 (CISA-ADP)Medium1.5.0 to 2.11.02.12.0
CVE-2026-68981Memory exhaustion through gzip-encoded REST API requests7.5 (NVD)High1.5.0 to 2.10.02.11.0
CVE-2026-68979Missing authorization for components referenced by Parameter Context updates9.8 (NVD)Medium1.10.0 to 2.10.02.11.0
CVE-2026-62354Read-only users can run Parameter Context validation with their own values4.3 (NVD)High1.10.0 to 2.10.02.11.0
CVE-2026-44914Restricted component permissions not checked when replacing Process Groups7.2 (NVD)High1.12.0 to 2.9.02.10.0
CVE-2026-44913SQL injection through table names in CaptureChangeMySQL7.2 (NVD)Medium1.2.0 to 2.9.02.10.0
CVE-2026-54665X-ProxyHost and X-Forwarded-Host headers not validated5.3 (NVD)Medium0.0.1 to 2.9.02.10.0
CVE-2026-44911Read-only users can run configuration verification with their own properties6.3 (NVD)Low1.15.0 to 2.9.02.10.0
CVE-2026-25903Restricted component permissions not checked on property updates6.6 (NVD)High1.1.0 to 2.7.22.8.0
CVE-2025-66524Deserialization of untrusted data in the GetAsanaObject processor8.8 (NVD)High1.20.0 to 2.6.02.7.0
CVE-2025-27017MongoDB username and password written to provenance events6.5 (NVD)Medium1.13.0 to 2.2.02.3.0
CVE-2024-56512Incomplete authorization for Parameter Context and service references when creating Process Groups5.4 (NVD)Low1.10.0 to 2.0.02.1.0
CVE-2026-87976NiFi Registry: crafted NAR coordinates write outside the extension bundle store8.1 (NVD)HighRegistry 0.4.0 to 2.11.0Registry 2.12.0

Most of these are authorization gaps that only matter where NiFi uses fine-grained, component-level policies. A deployment where every user has full write access is not exposed to them, because write access is already the security boundary there. The ones that do not depend on policy design are CVE-2026-68981, which a client can use to exhaust memory, CVE-2026-54665 on the proxy headers, CVE-2026-44913 for flows that use CaptureChangeMySQL, CVE-2025-66524 for flows that use GetAsanaObject, and CVE-2025-27017, which leaks MongoDB credentials to anyone who can read provenance.

NiFi 2.x

NiFi 2 needs Java 21. Each advisory names one fixed version, the next 2.x release, so staying on an older 2.x release means running without every fix since. Three 2.x CVEs do not reach 1.x: CVE-2026-39816 (8.8, missing Execute Code permission on TinkerpopClientService, fixed in 2.9.0), CVE-2026-68980 (9.1, authorization bypass for Parameter Context asset deletion, fixed in 2.11.0) and CVE-2026-70469 (7.5, a bypass of the 2.11.0 gzip block, fixed in 2.12.0). On 2.11.0, the CVE-2026-68981 fix is itself incomplete until 2.12.0.

NiFi 1.x

NiFi 1.28.1 fixed CVE-2024-52067 (4.9), which wrote sensitive parameter values to the debug log, and it is the last 1.x release with any fix. Earlier 1.x releases fixed CVE-2023-49145 in 1.24.0, CVE-2023-36542 (8.8) in 1.23.0 and CVE-2023-34468 (8.8) in 1.22.0, so a cluster still on 1.19 or 1.21 is missing those as well as the thirteen in the table. NiFi's migration guidance requires 1.27.0 or later before moving to 2.0, and 2.x removes the variable registry, flow.xml.gz and a long list of components, so the move takes planning. See Apache NiFi 1.x end of life and the NiFi 1.x to 2.0 upgrade guide.

Clustered NiFi 1.x also depends on ZooKeeper for coordinator election, often on an ensemble as old as the cluster. See ZooKeeper for NiFi.

What to do on each line

  • 2.x. Upgrade to 2.12.0. Fixes land only in new 2.x releases.
  • 1.x. Get to 1.28.1 if you are not there, then either migrate to 2.x or take patched builds from a supplier that backports fixes. Meanwhile, keep the REST API off untrusted networks, check who holds read access to provenance and Parameter Contexts, and validate proxy headers at the reverse proxy in front of NiFi.
  • NiFi Registry. Upgrade to Registry 2.12.0 for CVE-2026-87976, and plan the move to a Git-based flow registry client, since Registry is deprecated.

Where OSSeva fits

OSSeva backports NiFi security fixes across the 1.x line, including the Jetty, Jackson and Netty dependencies bundled in NiFi's NARs, with flow.xml.gz, NARs and parameter contexts unchanged. Builds ship as Docker images and tarballs, and are available now on the Patch, Assure and Operate tiers. Assure adds a processor and controller service inventory mapped against what 2.x removed and a costed flow migration plan, and Operate adds 24/7 dataflow monitoring with a 15-minute P1 response, named NiFi engineers and migration execution to 2.x. See Apache NiFi extended support.

Tags

Apache NiFiCVENiFi 1.xNiFi 2End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.