Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-68981

Apache NiFi: uncontrolled resource consumption through decompression of HTTP requests

Technology

Apache NiFi

CVSS Score

7.5 / 10.0

Affected Versions

1.5.0 to 2.10.0

Upstream Fix

2.11.0

Published

August 3, 2026

OSSeva Coverage

Fixed upstream

Description

The REST API accepted gzip-encoded requests and applied its maximum request size before decompression, so a small compressed request could expand into enough data to exhaust memory. Rated high by the NiFi project. Fixed in 2.11.0, which disabled gzip-encoded requests; CVE-2026-70469 later closed a bypass of that change in 2.12.0.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 1.5.0 to 2.10.0, you need this patch. Book a discovery call to get covered.