Impact
Apache NiFi 2.11.0 incorrectly handled the Content‑Encoding header for gzip‑encoded HTTP requests. The filter allowed multiple instances of the header and did not reject non‑standard identifiers for gzip, enabling an attacker to send specially crafted requests that cause the application to decompress unbounded data and consume excessive memory, potentially leading to a denial of service.
Affected Systems
The vulnerability affects Apache NiFi from the Apache Software Foundation, specifically version 2.11.0. Upgrading to 2.12.0 removes the issue by disabling gzip decompression handling for HTTP requests.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is below 1%, indicating low exploitation probability at the time of this analysis, and it is not listed in the CISA KEV catalog. The attack vector is remote over HTTP; an attacker can craft a request with multiple or malformed Content‑Encoding headers to trigger large memory consumption.
OpenCVE Enrichment