Memory Consumption Vulnerability in Apache NiFi by Apache
CVE-2026-68981

8.8HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
3 August 2026

What is CVE-2026-68981?

Apache NiFi versions 1.5.0 to 2.10.0 exhibit a vulnerability where improperly handled gzip-encoded HTTP requests can lead to excessive memory consumption. The application employs a Jersey encoding filter that enforces file size limits on compressed payloads instead of their decompressed counterparts, making it possible for attackers to exploit this flaw. The recommended mitigation is to upgrade to Apache NiFi version 2.11.0, which changes the response compression handling to Jetty Server and disables the decompression of gzip-encoded HTTP requests, thereby enhancing the security posture of the application.

Affected Version(s)

Apache NiFi 1.5.0 <= 2.10.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mak3bread (Minseong Kim)
.