Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-70469
Apache NiFi: Content-Encoding case and repetition bypass the gzip request block
Technology
Apache NiFi
CVSS Score
7.5 / 10.0
Affected Versions
2.11.0
Upstream Fix
2.12.0
Published
September 16, 2026
OSSeva Coverage
Fixed upstream
Description
NiFi 2.11.0 rejected gzip-encoded REST API requests to fix CVE-2026-68981, but its filter did not check repeated Content-Encoding headers or non-standard gzip identifiers, so a client could still send compressed requests that consume excessive memory. Rated high by the NiFi project. Fixed in 2.12.0, which stops decompressing gzip requests regardless of the headers.
Is your Apache NiFi deployment affected?
If you're running 2.11.0, you need this patch. Book a discovery call to get covered.