CVE-2026-68981: CWE-409 Improper Handling of Highly Compressed Data (Data Amplification) in Apache Software Foundation Apache NiFi
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.
AI Analysis
Technical Summary
Apache NiFi 1.5.0 through 2.10.0 supports gzip-encoded HTTP requests for its REST API using a Jersey encoding filter. The vulnerability arises because the framework enforces a configurable maximum request size on the compressed payload instead of the decompressed output. This improper handling of highly compressed data (CWE-409) can lead to data amplification, allowing a malicious client to cause excessive memory consumption on the server. The recommended mitigation is upgrading to Apache NiFi 2.11.0, which relocates response compression to the Jetty Server and disables decompression of gzip-encoded HTTP requests, thus preventing this attack vector.
Potential Impact
An attacker can exploit this vulnerability by sending specially crafted gzip-encoded HTTP requests that appear within allowed compressed size limits but decompress to a much larger size, causing excessive memory consumption on the server. This can lead to denial of service or resource exhaustion. The CVSS 4.0 score is 8.8 (high severity), indicating a significant impact on availability and resource usage without requiring authentication or user interaction.
Mitigation Recommendations
Upgrade Apache NiFi to version 2.11.0 or later. This version relocates response compression to the Jetty Server and disables decompression of gzip-encoded HTTP requests, effectively mitigating the vulnerability. No other mitigations are indicated or recommended by the vendor.
CVE-2026-68981: CWE-409 Improper Handling of Highly Compressed Data (Data Amplification) in Apache Software Foundation Apache NiFi
Description
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.
CVSS v4.0
Score 8.8high
Affected software
Apache Software Foundation
Apache NiFi
pkg:maven/org.apache.nifi/nifiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache NiFi 1.5.0 through 2.10.0 supports gzip-encoded HTTP requests for its REST API using a Jersey encoding filter. The vulnerability arises because the framework enforces a configurable maximum request size on the compressed payload instead of the decompressed output. This improper handling of highly compressed data (CWE-409) can lead to data amplification, allowing a malicious client to cause excessive memory consumption on the server. The recommended mitigation is upgrading to Apache NiFi 2.11.0, which relocates response compression to the Jetty Server and disables decompression of gzip-encoded HTTP requests, thus preventing this attack vector.
Potential Impact
An attacker can exploit this vulnerability by sending specially crafted gzip-encoded HTTP requests that appear within allowed compressed size limits but decompress to a much larger size, causing excessive memory consumption on the server. This can lead to denial of service or resource exhaustion. The CVSS 4.0 score is 8.8 (high severity), indicating a significant impact on availability and resource usage without requiring authentication or user interaction.
Mitigation Recommendations
Upgrade Apache NiFi to version 2.11.0 or later. This version relocates response compression to the Jetty Server and disables decompression of gzip-encoded HTTP requests, effectively mitigating the vulnerability. No other mitigations are indicated or recommended by the vendor.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-01T20:14:23.903Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a70f79ebf32cb7a34248238
Added to database: 08/03/2026, 20:18:38 UTC
Last enriched: 08/11/2026, 18:08:55 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 84
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.