Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-44913

Apache NiFi: improper escaping of table names in CaptureChangeMySQL

Technology

Apache NiFi

CVSS Score

7.2 / 10.0

Affected Versions

1.2.0 to 2.9.0

Upstream Fix

2.10.0

Published

June 22, 2026

OSSeva Coverage

Fixed upstream

Description

The CaptureChangeMySQL processor did not fully escape database table names, so crafted names could inject SQL commands. Installations that do not use CaptureChangeMySQL are not affected. Rated medium by the NiFi project; NVD scores it 7.2. Fixed in 2.10.0.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 1.2.0 to 2.9.0, you need this patch. Book a discovery call to get covered.