https://seclists.org/oss-sec/2026/q1/244: CVE-2025-59060: Apache Ranger: Hostname verification bypass in NiFigistryClient and NifiClient
Published Mar 2, 2026
·Updated
Affected Software
1 affected component
Apache Ranger<=2.7.0
Frequently Asked Questions
1
What is the severity of CVE-2025-59060?
The severity of CVE-2025-59060 is classified as low.
2
What versions of Apache Ranger are affected by CVE-2025-59060?
Apache Ranger versions through 2.7.0 are affected by CVE-2025-59060.
3
How do I fix CVE-2025-59060?
To fix CVE-2025-59060, users should upgrade to Apache Ranger version 2.8.0 or later.
4
What is the issue described in CVE-2025-59060?
CVE-2025-59060 describes a hostname verification bypass issue in the NiFiRegistryClient and NiFiClient components of Apache Ranger.
5
Who reported the CVE-2025-59060 vulnerability?
The CVE-2025-59060 vulnerability was reported by Nikita Mark.