CVE-2026-68981
Last modified
CVE-2026-68981 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Amber
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nifi | >= 1.5.0, < 2.11.0 |
References
- https://lists.apache.org/thread/vxrqn7poyf1wx6gdy7c0dxqfqkctjnggMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/08/03/13Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-68981?
How severe is CVE-2026-68981?
How do I fix CVE-2026-68981?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6897The Wishlist Member plugin for WordPress is vulnerable to un…8.8
- CVE-2026-68970Apache Airflow's Task SDK did not mask the contents of a Var…
- CVE-2026-68971Apache Airflow's asset materialization endpoint (`POST /api/…
- CVE-2026-68979Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Contex…9.8
- CVE-2026-6898The Wishlist Member plugin for WordPress is vulnerable to un…8.8
- CVE-2026-68980Apache NiFi 2.0.0 through 2.10.0 support creating, reading, …9.1
- CVE-2026-6899Check for certificate revocation only considers the first ma…5.6
- CVE-2026-6900Improper certificate validation vulnerability in B&R Industr…9.1
- CVE-2026-6901Untrusted Search Path vulnerability in B&R Industrial Automa…8.4
- CVE-2026-6902A Remote Code Execution vulnerability in P4 (Helix Core) Ser…7.7
- CVE-2026-6903The LabOne Web Server, backing the LabOne User Interface, co…8.7
- CVE-2026-6907An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5…5.3
Are you affected by CVE-2026-68981?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
