CVE-2026-70469: Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests
Apache NiFi CVE-2026-70469: duplicate or non-standard Content-Encoding headers bypass gzip request filtering in NiFi 2.11.0's REST API.
Apache NiFi disclosed CVE-2026-70469, rated High, affecting the Jetty-based REST API module (org.apache.nifi:nifi-jetty) in version 2.11.0. NiFi 2.11.0 disabled gzip-encoded HTTP requests and rejects those carrying the standard Content-Encoding header, but the framework enforcement filter fails to check multiple instances of the header and does not reject non-standard gzip identifiers, allowing crafted requests to evade the check. The disclosure was posted to oss-security by David Handermann.
- NiFi 2.11.0 rejects gzip-encoded REST API requests but the enforcement filter misses duplicate Content-Encoding headers.
- Non-standard gzip identifiers also evade the filter, per Apache's High-severity rating.
- Affects org.apache.nifi:nifi-jetty 2.11.0; disclosed on oss-security by David Handermann.
Coverage timelineoldest first · each row is one article
- · 10d agoCVE-2026-70469: Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests
oss-security· 45
Apache NiFi CVE-2026-70469: duplicate or non-standard Content-Encoding headers bypass gzip request filtering in NiFi 2.11.0's REST API.
- · 10d agoCVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration
oss-security· 24
Apache NiFi 2.9.0-2.11.0 Connector configuration update and verification APIs skip authorization for referenced Assets and Secrets (CVE-2026-81866, Low).
- · 10d ago
Vulnerabilities in this storyAll →
- CVE-2026-704697.5—Memory-exhaustion DoS via crafted Content-Encoding headers in Apache NiFi 2.11.0published · Apache Software Foundation Apache NiFi+4 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-70469+4 related CVEs | Memory-exhaustion DoS via crafted Content-Encoding headers in Apache NiFi 2.11.0 |