THE Apache Software Foundation has released updates for vulnerabilities affecting Apache NiFi and Apache MyFaces. The article lists no confirmed active exploitation. The most serious issue, CVE-2026-87976, is rated 7.2 (High, CVSSv4) and affects NiFi Registry 0.4.0 through 2.11.0. An authenticated user with permission to write and delete extension bundles could upload a NAR file containing a crafted manifest.
Because the default persistence provider used bundle coordinates as filesystem path components without rejecting parent-directory references, file operations could be performed outside the intended directory.
CVE-2026-70469 affects NiFi 2.11.0 and involves handling of HTTP requests containing multiple Content-Encoding headers or non-standard gzip identifiers. Crafted requests could consume excessive memory and crash the service. The article recommends upgrading NiFi to 2.12.0. A separate Apache MyFaces vulnerability, CVE-2026-76646, allows a remote attacker to cause excessive resource consumption through specially crafted request parameters, potentially resulting in denial of service. It affects branches 2.2.0 through 4.1.3; recommended fixed versions are 2.3.12, 3.0.4, 4.0.4 and 4.1.4.