securityonline.info 17 Sept 2026, 03:07 UTC

Apache Fixes NiFi Path Traversal and Denial of Service Flaws

Apache Fixes NiFi Path Traversal and Denial of Service Flaws

THE Apache Software Foundation has released updates for vulnerabilities affecting Apache NiFi and Apache MyFaces. The article lists no confirmed active exploitation. The most serious issue, CVE-2026-87976, is rated 7.2 (High, CVSSv4) and affects NiFi Registry 0.4.0 through 2.11.0. An authenticated user with permission to write and delete extension bundles could upload a NAR file containing a crafted manifest.

Because the default persistence provider used bundle coordinates as filesystem path components without rejecting parent-directory references, file operations could be performed outside the intended directory.

CVE-2026-70469 affects NiFi 2.11.0 and involves handling of HTTP requests containing multiple Content-Encoding headers or non-standard gzip identifiers. Crafted requests could consume excessive memory and crash the service. The article recommends upgrading NiFi to 2.12.0. A separate Apache MyFaces vulnerability, CVE-2026-76646, allows a remote attacker to cause excessive resource consumption through specially crafted request parameters, potentially resulting in denial of service. It affects branches 2.2.0 through 4.1.3; recommended fixed versions are 2.3.12, 3.0.4, 4.0.4 and 4.1.4.

View full article

Article by CyberSIXT