Skip to main content
Components
Vulnerabilities
Pricing
MCP
API
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
org.apache.nifi.registry/nifi-registry-web… | Sonatype Guide
Get full component data and automated fixes with Sonatype Guide.
Sign up for free
maven
org.apache.nifi.registry
nifi-registry-web-api
2.11.0
nifi-registry-web-api 2.11.0
Latest
org.apache.nifi.registry
Published
Jul 30, 2026
•
Policy
compliance
maven Registry
Developer Trust Score
Recommended Version:
x.y.z
Recommended upgrade that meets your policy.
Compare Versions
Overview
Overview
Versions
50
Versions
50
Vulnerabilities
9
Vulnerabilities
9
Dependencies
0
Dependencies
0
Severity
Critical
(1)
High
(4)
Medium
(2)
Low
(2)
CVSS Score
0.0
10.0
EPSS Score
0.0
1.0
Malware
KEV Status
Published
Filter
Sort: Published (Newest first)
8.7
sonatype-2026-005959
jackson-databind - Deserialization of untrusted data
affected
Severity
High
Published
Aug 11, 2026
8.7
CVE-2026-68497
jackson-databind - Allocation of Resources Without Limits or Throttling
affected
Severity
High
Published
Aug 10, 2026
6.9
CVE-2026-19032
com.fasterxml.jackson.core/jackson-databind - Unrestricted URI schemes in Path deserialization
affected
Severity
Medium
Published
Aug 10, 2026
2.0
CVE-2026-14686
A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range Check. Performing a manipulation results in incorrect comparison. The attack is only possible with local access. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.
affected
Severity
Low
Published
Jul 6, 2026
2.0
CVE-2026-14683
A vulnerability was detected in HdrHistogram up to 2.2.2. Affected by this issue is the function org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. The manipulation of the argument lengthOfCompressedContents results in uncontrolled memory allocation. The attack needs to be approached locally. The exploit is now public and may be used. It is still unclear if this vulnerability genuinely exists. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.
affected
Severity
Low
Published
Jul 6, 2026
8.1
CVE-2026-47838
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.
affected
Severity
High
Published
Jun 10, 2026
6.0
sonatype-2018-0863
h2database - Improper Link Resolution Before File Access
affected
Severity
Medium
Published
Aug 18, 2022
9.8
CVE-2017-15697
A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
affected
Severity
Critical
Published
Jul 23, 2018
7.5
CVE-2017-12632
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
affected
Severity
High
Published
Jul 20, 2018