ZeroHour
oss-securitypublished ()ingested

CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles

AI summary · glm-5.3-flash

Apache NiFi Registry 0.4.0-2.11.0 allows path manipulation when storing extension bundle content from uploaded NAR manifests (CVE-2026-87976, High).

Apache NiFi Registry versions 0.4.0 through 2.11.0 are affected by improper limitation of a pathname (CVE-2026-87976), rated High severity by the maintainers. When storing extension bundle content, the default file persistence provider used group, artifact, and version coordinates from uploaded NAR manifests as filesystem path components without sufficient validation. The disclosure was posted by Apache NiFi maintainer David Handermann on the oss-security mailing list.

  • Affects Apache NiFi Registry 0.4.0 through 2.11.0 (nifi-registry-framework artifact)
  • Path manipulation occurs via group, artifact, and version coordinates from NAR manifests
  • Default file persistence provider lacks pathname validation
  • Rated High severity in the official Apache disclosure

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87976

NVD description · AI analysis pending
Full article

Posted by David Handermann on Sep 16 Severity: High Affected versions: - Apache NiFi Registry (org.apache.nifi.registry:nifi-registry-framework) 0.4.0 through 2.11.0 Description: Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected...

This source does not provide full text. Read it at seclists.org.