
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59060 is a hostname verification bypass vulnerability in Apache Ranger's NiFiRegistryClient and NiFiClient components, affecting all versions up to and including 2.7.0. The flaw was discovered by Nikita Markevich and publicly disclosed on March 2, 2026 via the oss-security mailing list. It carries a CVSS v3.1 base score of 5.3 (Medium), with no authentication or user interaction required for exploitation (Apache oss-security, Red Hat).
The vulnerability is classified as CWE-297 (Improper Validation of Certificate with Host Mismatch). Apache Ranger's NiFiRegistryClient and NiFiClient fail to properly validate that the hostname in a TLS/SSL certificate matches the server being connected to, allowing an attacker to present a valid certificate issued for a different hostname and have it accepted. This enables a network-positioned adversary to intercept or manipulate TLS-protected communications between Ranger and NiFi/NiFi Registry services without triggering certificate validation errors (Apache oss-security, Red Hat).
Successful exploitation allows an attacker with network access to conduct man-in-the-middle (MITM) attacks against communications between Apache Ranger's NiFi clients and backend NiFi/NiFi Registry services. The primary impact is unauthorized disclosure of sensitive data in transit (low confidentiality impact), with no direct effect on integrity or availability. In environments where Ranger manages access policies for sensitive data pipelines, intercepted traffic could expose credentials, policy data, or other confidential information (Red Hat, Apache oss-security).
NiFiRegistryClient or NiFiClient and present the attacker-controlled certificate during the handshake.The primary remediation is to upgrade Apache Ranger to version 2.8.0 or later, which resolves the hostname verification bypass. For organizations unable to patch immediately, recommended interim controls include restricting network access to NiFi and NiFi Registry services using firewall rules or network segmentation, implementing certificate pinning where feasible, and monitoring application logs for certificate validation anomalies. Upgrading to 2.8.0 is the only definitive fix (Apache oss-security, Red Hat).
The vulnerability was reported by security researcher Nikita Markevich and disclosed by Apache Ranger maintainer Velmurugan Periasamy via the oss-security mailing list with a severity rating of "low." Red Hat has tracked the issue in their security advisory database. Community reaction has been limited given the medium/low severity and absence of public exploits, with standard aggregation by vulnerability databases and threat intelligence platforms (Apache oss-security, Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."