Apache fixes two DoS flaws in NiFi and MyFaces
Apache's October 2026 round patches CVE-2026-70469 in NiFi 2.11.0 and CVE-2026-76646 in MyFaces 2.2.0–4.1.3. Both cause resource exhaustion and denial of service; fixes ship in NiFi 2.12.0 and MyFaces 2.3.12, 3.0.4, 4.0.4 and 4.1.4. No active exploitation was confirmed.
- CVE-2026-70469 in NiFi 2.11.0: DoS via Content-Encoding handling
- CVE-2026-76646 in MyFaces 2.2.0–4.1.3: DoS via request parameters
- Patched releases: NiFi 2.12.0 and MyFaces 2.3.12, 3.0.4, 4.0.4, 4.1.4
- No active exploitation confirmed for either flaw
Read next
Security