Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-54665
Apache NiFi: missing validation of proxy host headers
Technology
Apache NiFi
CVSS Score
5.3 / 10.0
Affected Versions
0.0.1 to 2.9.0
Upstream Fix
2.10.0
Published
June 22, 2026
OSSeva Coverage
Fixed upstream
Description
NiFi builds qualified URLs from proxy headers such as X-ProxyHost and X-Forwarded-Host, and did not validate them against the allowed host list it applies to the Host header. A client could make NiFi construct invalid URLs for redirects or data references. Rated medium by the NiFi project. Fixed in 2.10.0, which validates those headers against nifi.web.proxy.host when HTTPS is configured.
Is your Apache NiFi deployment affected?
If you're running 0.0.1 to 2.9.0, you need this patch. Book a discovery call to get covered.