CVE-2026-68981Disclosure(apache / nifi)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache nifi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-409

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nifi

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-04); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
nifi

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-04: 3Mentions · 2026-08-12: 1Patch / Workaround · 2026-08-04: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-04: 3Technical Details · 2026-08-12: 108-0408-12
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-043
Disclosure2Patch1
2026-08-121
Patch1
Full discourse4 posts
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption. #ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec http://securityonline.info/apache-nifi-vulnerabilities/

    Post summary

    The tweet announces multiple Apache NiFi CVEs that enable code execution and excessive resource usage, without providing PoC details, exploits, or mitigation information.

    01040453
    12.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Apache NiFi の 4件の脆弱性が FIX:コンフィグ設定の改竄やサービス拒否状態の恐れ https://iototsecnews.jp/2026/08/04/apache-nifi-vulnerabilities-enable-authorization-bypass-attacks/ Apache NiFi の Web API や Parameter Context における認可制御の不備などに起因する複数の脆弱性 (CVE-2026-62354/CVE-2026-68979/CVE-2026-68980/CVE-2026-68981) が確認されています。これらの欠陥を悪用されると、不正な設定変更やメモリ枯渇によるサービス停止、場合によってはコード実行を引き起こされる恐れがあります。システムを安全に利用するためにも、対象コンポーネントを最新版の Apache NiFi 2.11.0 へ速やかに更新し、アクセス権限や設定値の再確認を進めることが推奨されます。 #ApacheNiFi #CVE202662354 #CVE202668979 #CVE202668980 #CVE202668981 #Vulnerability #AuthNAuthZ #OpenSource

    Post summary

    Apache NiFi is affected by four CVEs (CVE‑2026‑62354, ‑68979, ‑68980, ‑68981) that can lead to unauthorized configuration changes, denial‑of‑service, or code execution; users are advised to upgrade to version 2.11.0 immediately.

    01000132
    507 followersView on X
  • VulniPulse@vulnipulse
    Disclosure

    ⚠️ HIGH CVE ALERT CVE-2026-68981 · Apache NiFi · CVSS 8.8 Malicious clients could consume excessive memory. 🔎 Full advisory: https://vulnipulse.com/advisories/apache-cve-2026-68981 #CyberSecurity #CVE #Apache #ApacheNiFi

    Post summary

    The advisory announces CVE-2026-68981 for Apache NiFi, highlighting a memory exhaustion vulnerability with a CVSS score of 8.8, but does not provide a PoC, exploit, active usage, patch, or debunking information.

    1000055
    7 followersView on X
  • TECHEPAGES@techepages
    Patch

    Apache has disclosed four security vulnerabilities in Apache NiFi affecting the Web API and Parameter Context authorization controls (versions 1.5.0–2.10.0). All issues are resolved in version 2.11.0. CVE-2026-68981 (High) — Improper enforcement of request size limits on gzip-compressed payloads, enabling memory exhaustion/DoS CVE-2026-62354 (High) — Authorization bypass allowing read-only users to influence component validation via crafted Parameter values CVE-2026-68979 (Medium) — Missing authorization checks on components referencing updated Parameter Contexts; potential code execution in specific configurations CVE-2026-68980 (Low) — Insufficient ownership verification during Asset deletion Organizations running affected versions are advised to upgrade to NiFi 2.11.0

    Post summary

    Apache disclosed four NiFi CVEs with technical details and a patch recommendation (upgrade to version 2.11.0); no PoC, exploit code, or active exploitation was reported.

    0000039
    35 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachenifi---

Explore more