Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-66524

29
FAUCET Score

CVE-2025-66524 is a critical deserialization vulnerability affecting Apache NiFi versions 1.20.0 through 2.6.0, specifically within the GetAsanaObject Processor. This flaw allows for arbitrary code execution due to unfiltered Java object deserialization when storing and retrieving state information from a configured cache server. With a CVSS score of 8.8 (High), successful exploitation requires an attacker to have direct access to the cache server used by the GetAsanaObject Processor, potentially leading to full compromise of the NiFi system. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.20.0, <= 2.6.0CPE match
cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*
>= 1.20.0, < 2.7.0CPE matchmatch criteria
cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*
2.7.0CPE matchmatch criteria
cpe:2.3:a:apache:nifi:2.7.0:rc1:*:*:*:*:*:*
2.7.0CPE matchmatch criteria
cpe:2.3:a:apache:nifi:2.7.0:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.5HIGH

CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:Green

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.44%
Probability of exploitation in next 30 days
EPSS Percentile
36.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0044 is in the 24th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: org.apache.nifi:nifi-asana-processorsFixed in: 2.7.0

Vendor Advisories (1)

mavenGHSA-v4p2-2w39-mhrjhigh

Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe Deserialization

Dec 19, 2025

References

openwall.com / lists/oss-security/2025/12/18/2
Mailing List
lists.apache.org / thread/k9h004ydjg7opdvxr0nfywtzf33z60d7
Issue TrackingMailing ListVendor Advisory