ZeroHour
Organization

ASF

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

CVE-2026-41869: Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)

Apache Nutch CVE-2026-41869 (moderate) lets unauthenticated users force shutdown or interrupt jobs via the Nutch Server REST API; fixed in 1.23.

A missing authorization and improper resource shutdown flaw in the Nutch Server REST API allows unauthenticated users to force a shutdown or interrupt running jobs. Apache Nutch versions 1.10 through 1.22 are affected. Version 1.23 fixes the issue by removing the Nutch Server; where upgrading is not possible, administrators must restrict access to instances running Nutch Server.

CVE-2026-84939: Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks

Apache FreeMarker CVE-2026-84939 permits path traversal via a malformed locale in template loading; fixed in FreeMarker 2.3.35.

A path traversal vulnerability in Apache FreeMarker's template loading mechanism can be triggered when an attacker controls a malformed locale value. FreeMarker 2.2.0 through 2.3.34 are affected for both the org.freemarker:freemarker and freemarker-gae artifacts, while 2.3.35 is unaffected. No exploitation or CVSS details were included in the announcement.

oss-security · 7d agoVulnerabilityCVE-2026-84939

Related CVEs

  • Unauthenticated job interruption and shutdown in Apache Nutch Server REST API
    Apache Nutch 1.10 through 1.22 ship a Nutch Server (REST API) component that fails to enforce authorization (CWE-862) and handles resource shutdown and job lifecycle incorrectly (CWE-404). An unauthenticated attacker who can reach the Nutch REST API can issue requests that force the Nutch server to shut down and interrupt any crawl jobs in progress. The impact is denial of service and loss of in-flight crawl work; there is no indication of remote code execution or data compromise. Anyone running the affected Nutch versions with the Nutch Server/REST API enabled and reachable by untrusted users is affected. No public proof-of-concept is known, the issue is not in CISA KEV, and there are no confirmed reports of in-the-wild exploitation.
    · Apache Software Foundation Apache Nutch (Nutch Server / Nutch REST API) 1.10 through 1.22 (fixed in 1.23, which removes the Nutch Server)niche
  • Path Traversal in Apache FreeMarker Localized Template Lookup (CVE-2026-84939)
    Apache FreeMarker is vulnerable to path traversal (CWE-23) in its template loading mechanism when the localized lookup configuration setting is enabled, which is the default. The flaw is triggered if an application allows an attacker to supply an arbitrary, malformed locale identifier to FreeMarker; the malformed locale can cause template loading to traverse outside the intended path. What an attacker gains depends on configuration: files that can be loaded remain restricted by the configured TemplateLoader — FileTemplateLoader already prevents traversal outside its baseDir, and loaders wrapping a class loader or web application context can only reach resources those mechanisms expose — but other loader configurations may allow access outside the designated base directory, potentially enabling unintended file or resource disclosure. Any application embedding Apache FreeMarker versions 2.2.0 through 2.3.34 that passes attacker-controlled locale values into template loading is affected, including downstream products that bundle the library. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
    · Apache FreeMarker 2.2.0 through 2.3.34 (fixed in 2.3.35)mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.