
CVE-2025-59060: Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient https://www.openwall.com/lists/oss-security/2026/03/02/4 CVE-2025-59059: Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator https://www.openwall.com/lists/oss-security/2026/03/02/5 Both are "Severity: low"
Post summary
An email list post discloses two low‑severity Apache Ranger CVEs: a hostname‑verification bypass in the NiFiRegistryClient and NifiClient, and a remote code execution flaw in NashornScriptEngineCreator.



