Input validation error in Apache Nifi - CVE-2026-54665
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause generation of invalid qualified URLs for redirection or data references.
The vulnerability exists due to improper input validation in proxy and forwarded host header handling when processing HTTP requests with alternative host headers. A remote attacker can supply crafted X-ProxyHost or X-Forwarded-Host header values to cause generation of invalid qualified URLs for redirection or data references.
The issue affects qualified URL construction based on alternative headers used instead of the standard Host header.