Missing Authorization and Resource Shutdown Flaws in Apache Nutch Server
CVE-2026-41869

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 September 2026

What is CVE-2026-41869?

The Apache Nutch Server has a vulnerability that stems from missing authorization checks and improper resource shutdown mechanisms, impacting the Nutch REST API functionality. This allows users to potentially access restricted services and disrupt ongoing tasks. To mitigate these risks, users are advised to upgrade to Nutch version 1.23, which eliminates the vulnerable server version, or restrict service access to trusted users only. For more details, please refer to the Apache Nutch security advisories.

Affected Version(s)

Apache Nutch 1.10 <= 1.22

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Nutch Project Management Committee would like to thank Th1nk for reporting this issue.
.