Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-54665

Apache NiFi: missing validation of proxy host headers

Technology

Apache NiFi

CVSS Score

5.3 / 10.0

Affected Versions

0.0.1 to 2.9.0

Upstream Fix

2.10.0

Published

June 22, 2026

OSSeva Coverage

Fixed upstream

Description

NiFi builds qualified URLs from proxy headers such as X-ProxyHost and X-Forwarded-Host, and did not validate them against the allowed host list it applies to the Host header. A client could make NiFi construct invalid URLs for redirects or data references. Rated medium by the NiFi project. Fixed in 2.10.0, which validates those headers against nifi.web.proxy.host when HTTPS is configured.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 0.0.1 to 2.9.0, you need this patch. Book a discovery call to get covered.