Input validation error in Apache Nifi - CVE-2026-54665

 

Input validation error in Apache Nifi - CVE-2026-54665

Published: August 25, 2026


Vulnerability identifier: #VU145263
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54665
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause generation of invalid qualified URLs for redirection or data references.

The vulnerability exists due to improper input validation in proxy and forwarded host header handling when processing HTTP requests with alternative host headers. A remote attacker can supply crafted X-ProxyHost or X-Forwarded-Host header values to cause generation of invalid qualified URLs for redirection or data references.

The issue affects qualified URL construction based on alternative headers used instead of the standard Host header.


Affected software

Apache Nifi

How to mitigate CVE-2026-54665

Install security update from vendor's website.

Apache Nifi - update to 2.10.0

External References

Related Security Bulletins