ZeroHour
Product

Nutch Server

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

CVE-2026-41869: Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)

Apache Nutch CVE-2026-41869 (moderate) lets unauthenticated users force shutdown or interrupt jobs via the Nutch Server REST API; fixed in 1.23.

A missing authorization and improper resource shutdown flaw in the Nutch Server REST API allows unauthenticated users to force a shutdown or interrupt running jobs. Apache Nutch versions 1.10 through 1.22 are affected. Version 1.23 fixes the issue by removing the Nutch Server; where upgrading is not possible, administrators must restrict access to instances running Nutch Server.

Related CVEs

  • Unauthenticated job interruption and shutdown in Apache Nutch Server REST API
    Apache Nutch 1.10 through 1.22 ship a Nutch Server (REST API) component that fails to enforce authorization (CWE-862) and handles resource shutdown and job lifecycle incorrectly (CWE-404). An unauthenticated attacker who can reach the Nutch REST API can issue requests that force the Nutch server to shut down and interrupt any crawl jobs in progress. The impact is denial of service and loss of in-flight crawl work; there is no indication of remote code execution or data compromise. Anyone running the affected Nutch versions with the Nutch Server/REST API enabled and reachable by untrusted users is affected. No public proof-of-concept is known, the issue is not in CISA KEV, and there are no confirmed reports of in-the-wild exploitation.
    · Apache Software Foundation Apache Nutch (Nutch Server / Nutch REST API) 1.10 through 1.22 (fixed in 1.23, which removes the Nutch Server)niche

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.