Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-70469

Apache NiFi: Content-Encoding case and repetition bypass the gzip request block

Technology

Apache NiFi

CVSS Score

7.5 / 10.0

Affected Versions

2.11.0

Upstream Fix

2.12.0

Published

September 16, 2026

OSSeva Coverage

Fixed upstream

Description

NiFi 2.11.0 rejected gzip-encoded REST API requests to fix CVE-2026-68981, but its filter did not check repeated Content-Encoding headers or non-standard gzip identifiers, so a client could still send compressed requests that consume excessive memory. Rated high by the NiFi project. Fixed in 2.12.0, which stops decompressing gzip requests regardless of the headers.

Upstream record: NVD · CVE.org

Is your Apache NiFi deployment affected?

If you're running 2.11.0, you need this patch. Book a discovery call to get covered.