https://seclists.org/oss-sec/2026/q3/804: CVE-2026-70469: Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP quests
Published Sep 16, 2026
·Updated
Affected Software
1 affected component
Apache nifi=2.11.0
Frequently Asked Questions
1
Which systems are affected?
Apache NiFi installations using org.apache.nifi:nifi-jetty version 2.11.0 are affected. The issue concerns HTTP requests to the application REST API.
2
What does an attacker need to send to trigger the issue?
A malicious client must send crafted HTTP requests that bypass the intended rejection of gzip-encoded content. The bypass can use multiple Content-Encoding headers or non-standard identifiers for gzip encoding.
3
What is the recommended mitigation?
Upgrade to Apache NiFi 2.12.0. This version disables decompression of gzip-encoded HTTP requests regardless of the number of Content-Encoding headers or the encoding identifiers used.