CVE-2025-59060
Java vulnerability analysis and mitigation

Overview

CVE-2025-59060 is a hostname verification bypass vulnerability in Apache Ranger's NiFiRegistryClient and NiFiClient components, affecting all versions up to and including 2.7.0. The flaw was discovered by Nikita Markevich and publicly disclosed on March 2, 2026 via the oss-security mailing list. It carries a CVSS v3.1 base score of 5.3 (Medium), with no authentication or user interaction required for exploitation (Apache oss-security, Red Hat).

Technical details

The vulnerability is classified as CWE-297 (Improper Validation of Certificate with Host Mismatch). Apache Ranger's NiFiRegistryClient and NiFiClient fail to properly validate that the hostname in a TLS/SSL certificate matches the server being connected to, allowing an attacker to present a valid certificate issued for a different hostname and have it accepted. This enables a network-positioned adversary to intercept or manipulate TLS-protected communications between Ranger and NiFi/NiFi Registry services without triggering certificate validation errors (Apache oss-security, Red Hat).

Impact

Successful exploitation allows an attacker with network access to conduct man-in-the-middle (MITM) attacks against communications between Apache Ranger's NiFi clients and backend NiFi/NiFi Registry services. The primary impact is unauthorized disclosure of sensitive data in transit (low confidentiality impact), with no direct effect on integrity or availability. In environments where Ranger manages access policies for sensitive data pipelines, intercepted traffic could expose credentials, policy data, or other confidential information (Red Hat, Apache oss-security).

Exploitation steps

  1. Positioning: Attain a network-adjacent or on-path position between an Apache Ranger instance (running version ≤ 2.7.0) and its configured NiFi or NiFi Registry backend service (e.g., via ARP spoofing, DNS poisoning, or rogue network device).
  2. Certificate preparation: Obtain or generate a valid TLS certificate for any hostname (e.g., a legitimately issued certificate for an attacker-controlled domain, or a self-signed certificate if the trust store is permissive).
  3. Intercept TLS handshake: Intercept the TLS connection initiated by NiFiRegistryClient or NiFiClient and present the attacker-controlled certificate during the handshake.
  4. Bypass hostname check: Because Ranger does not properly validate that the certificate's Common Name or Subject Alternative Names match the intended NiFi/NiFi Registry hostname, the connection proceeds without error.
  5. Decrypt and relay traffic: Decrypt the intercepted traffic to access sensitive data (e.g., API tokens, policy configurations, data flow metadata) and optionally relay requests to the legitimate backend to avoid detection (Apache oss-security).

Indicators of compromise

  • Network: Unexpected TLS certificate CN/SAN mismatches observed in network inspection tools between Ranger and NiFi/NiFi Registry endpoints; unusual intermediate hosts appearing in network flow data on NiFi communication ports.
  • Logs: TLS handshake anomalies or certificate warnings in Apache Ranger application logs; connections to NiFi services originating from unexpected IP addresses.
  • Process/Configuration: Unexpected changes to DNS resolution for NiFi/NiFi Registry hostnames; ARP table anomalies on network segments hosting Ranger services.

Mitigation and workarounds

The primary remediation is to upgrade Apache Ranger to version 2.8.0 or later, which resolves the hostname verification bypass. For organizations unable to patch immediately, recommended interim controls include restricting network access to NiFi and NiFi Registry services using firewall rules or network segmentation, implementing certificate pinning where feasible, and monitoring application logs for certificate validation anomalies. Upgrading to 2.8.0 is the only definitive fix (Apache oss-security, Red Hat).

Community reactions

The vulnerability was reported by security researcher Nikita Markevich and disclosed by Apache Ranger maintainer Velmurugan Periasamy via the oss-security mailing list with a severity rating of "low." Red Hat has tracked the issue in their security advisory database. Community reaction has been limited given the medium/low severity and absence of public exploits, with standard aggregation by vulnerability databases and threat intelligence platforms (Apache oss-security, Red Hat).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p279-2cqp-84jgCRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesJul 24, 2026
GHSA-fp43-vj7g-pg92HIGH7.5
  • Java logoJava
  • org.omnifaces:omnifaces
NoYesJul 24, 2026
GHSA-7ppr-r889-mcf2HIGH7.5
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.12
NoYesJul 24, 2026
GHSA-mhvj-jhpq-885vHIGH7.4
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.13
NoYesJul 24, 2026
GHSA-46q4-43ph-c6frHIGH7.4
  • Java logoJava
  • org.http4s:blaze-http_2.12
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management