VYPR

apk package

chainguard/apache-nifi-registry-2.11

pkg:apk/chainguard/apache-nifi-registry-2.11

Vulnerabilities (3)

  • CVE-2026-64607MedJul 31, 2026
    affected < 2.11.0-r2fixed 2.11.0-r2

    HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient bas

  • CVE-2026-41001MedJun 11, 2026
    affected < 2.11.0-r3fixed 2.11.0-r3

    Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the appl

  • CVE-2026-41706MedJun 10, 2026
    affected < 2.11.0-r1fixed 2.11.0-r1

    Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute URL is stored in the