https://seclists.org/oss-sec/2025/q4/286: CVE-2025-66524: Apache NiFi: Deserialization of Untrusted Data in GetAsanaObject Processor
Published Dec 18, 2025
·Updated
Affected Software
2 affected components
Apache nifi>=1.20.0<=2.6.0
maven/org.apache.nifi/nifi-asana-processors>=1.20.0<=2.6.0
Frequently Asked Questions
1
What is the severity of CVE-2025-66524?
CVE-2025-66524 has been classified with a severity rating that indicates potential risk for users of affected Apache NiFi versions.
2
How do I fix CVE-2025-66524?
To remediate CVE-2025-66524, you should update Apache NiFi to a version later than 2.6.0 where the vulnerability is addressed.
3
Which versions of Apache NiFi are affected by CVE-2025-66524?
CVE-2025-66524 affects Apache NiFi versions from 1.20.0 through 2.6.0.
4
What product is impacted by CVE-2025-66524?
CVE-2025-66524 impacts the GetAsanaObject Processor in Apache NiFi.
5
What type of vulnerability is CVE-2025-66524?
CVE-2025-66524 is a vulnerability related to the deserialization of untrusted data.