<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 17:47:11 +0000</lastBuildDate>
    <item>
      <title>BIT-nifi-2026-68981 — Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests</title>
      <link>https://cve.radiocsirt.org/vuln/bit-nifi-2026-68981</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: nifi&lt;/p&gt;
&lt;p&gt;Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: nifi&lt;/p&gt;
&lt;p&gt;Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-nifi-2026-68981</guid>
    </item>
    <item>
      <title>EUVD-2026-344238</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344238</link>
      <description>EUVD-2026-344238</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344238</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68981</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68981</link>
      <description>&lt;p&gt;Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68981</guid>
    </item>
    <item>
      <title>GHSA-w96g-mj2p-wqjv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w96g-mj2p-wqjv</link>
      <description>&lt;p&gt;Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w96g-mj2p-wqjv</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2639 — Apache Nifi: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2639</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache Nifi ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder möglicherweise beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache Nifi ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder möglicherweise beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2639</guid>
    </item>
  </channel>
</rss>
