ZeroHour
Product

Apache Nutch

0 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

CVE-2026-41871: Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)

Apache fixed CVE-2026-41871, an unauthenticated unsafe-reflection job execution flaw in Nutch Server's REST API affecting versions 1.10-1.22.

CVE-2026-41871 describes a Missing Authorization and Unsafe Reflection vulnerability in Apache Nutch Server (the Nutch REST API), rated important by Apache. Affected versions are Apache Nutch 1.10 through 1.22, allowing unauthenticated reflection-based job execution via externally controlled class selection. Users are recommended to upgrade to version 1.23, which removes the Nutch Server; users who cannot upgrade must apply mitigations.

CVE-2026-41870: Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)

Apache fixed CVE-2026-41870, a critical unauthenticated RCE via JEXL injection in Nutch Server's REST API affecting versions 1.11-1.22.

CVE-2026-41870 describes a critical Missing Authorization and Code Injection vulnerability in Apache Nutch Server (the Nutch REST API), enabling unauthenticated remote code execution via JEXL injection. Affected versions are Apache Nutch 1.11 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server; users who cannot upgrade must apply mitigations.

CVE-2026-41869: Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)

Apache Nutch CVE-2026-41869 (moderate) lets unauthenticated users force shutdown or interrupt jobs via the Nutch Server REST API; fixed in 1.23.

A missing authorization and improper resource shutdown flaw in the Nutch Server REST API allows unauthenticated users to force a shutdown or interrupt running jobs. Apache Nutch versions 1.10 through 1.22 are affected. Version 1.23 fixes the issue by removing the Nutch Server; where upgrading is not possible, administrators must restrict access to instances running Nutch Server.

Related CVEs

  • Unauthenticated reflection-based job execution in Apache Nutch Server REST API
    CVE-2026-41871 is a missing-authorization flaw (CWE-862) combined with unsafe reflection (CWE-470) in the Nutch Server component, i.e., the Nutch REST API, affecting Apache Nutch versions 1.10 through 1.22. The REST API fails to properly authorize requests, so unauthenticated or untrusted users can send API calls whose externally controlled input determines which classes or code are loaded and executed. An attacker who can reach the exposed Nutch Server can therefore trigger reflection-based job execution, potentially running arbitrary classes or jobs on the server. Only deployments running the optional Nutch Server (REST API) on Nutch 1.10 through 1.22 are affected. There is currently no public proof of concept, no known in-the-wild exploitation, and the issue is not in CISA KEV; the CVSS score has not yet been assigned.
    · Apache Nutch (Nutch Server / Nutch REST API) 1.10 through 1.22; fixed in 1.23, which removes the Nutch Serverniche
  • Unauthenticated job interruption and shutdown in Apache Nutch Server REST API
    Apache Nutch 1.10 through 1.22 ship a Nutch Server (REST API) component that fails to enforce authorization (CWE-862) and handles resource shutdown and job lifecycle incorrectly (CWE-404). An unauthenticated attacker who can reach the Nutch REST API can issue requests that force the Nutch server to shut down and interrupt any crawl jobs in progress. The impact is denial of service and loss of in-flight crawl work; there is no indication of remote code execution or data compromise. Anyone running the affected Nutch versions with the Nutch Server/REST API enabled and reachable by untrusted users is affected. No public proof-of-concept is known, the issue is not in CISA KEV, and there are no confirmed reports of in-the-wild exploitation.
    · Apache Software Foundation Apache Nutch (Nutch Server / Nutch REST API) 1.10 through 1.22 (fixed in 1.23, which removes the Nutch Server)niche
  • Unauthenticated RCE via JEXL injection in Apache Nutch REST API
    The Nutch Server component of Apache Nutch (its REST API) fails to require authorization for requests (CWE-862) and allows externally controlled input to select classes and dynamically managed code resources (CWE-470, CWE-913), culminating in JEXL (Java Expression Language) injection that is evaluated server-side (CWE-94). An unauthenticated attacker who can reach the Nutch REST API can send crafted requests whose injected expressions are executed by the server, gaining remote code execution in the context of the Nutch process. All Apache Nutch releases from 1.11 through 1.22 are affected when the Nutch Server is running; version 1.23 resolves the issue by removing the Nutch Server entirely. No CVSS score has been assigned yet, the flaw is not in CISA's KEV, and no public proof-of-concept or confirmed in-the-wild exploitation is known.
    · Apache Nutch (Nutch Server / Nutch REST API) 1.11 through 1.22 (inclusive); fixed in 1.23, which removes the Nutch Serverniche

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.