Skip to main content
Components
Vulnerabilities
Pricing
MCP
API
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
org.apache.nifi.registry/nifi-registry-web… | Sonatype Guide
Get full component data and automated fixes with Sonatype Guide.
Sign up for free
maven
org.apache.nifi.registry
nifi-registry-web-api
2.11.0
nifi-registry-web-api 2.11.0
Latest
org.apache.nifi.registry
Published
Jul 30, 2026
•
Policy
compliance
maven Registry
Developer Trust Score
Recommended Version:
x.y.z
Recommended upgrade that meets your policy.
Compare Versions
Overview
Overview
Versions
50
Versions
50
Vulnerabilities
9
Vulnerabilities
9
Dependencies
0
Dependencies
0
Reset filters
Severity
Critical
(0)
High
(4)
Medium
(0)
Low
(0)
CVSS Score
0.0
10.0
EPSS Score
0.0
1.0
Malware
KEV Status
Published
Filter
Sort: Published (Newest first)
8.7
sonatype-2026-005959
jackson-databind - Deserialization of untrusted data
affected
Severity
High
Published
Aug 11, 2026
8.7
CVE-2026-68497
jackson-databind - Allocation of Resources Without Limits or Throttling
affected
Severity
High
Published
Aug 10, 2026
8.1
CVE-2026-47838
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.
affected
Severity
High
Published
Jun 10, 2026
7.5
CVE-2017-12632
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
affected
Severity
High
Published
Jul 20, 2018