Missing Authorization and Code Injection Vulnerability in Apache Nutch Server
CVE-2026-41870

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 September 2026

What is CVE-2026-41870?

A vulnerability in the Apache Nutch Server allows for improper control and generation of code, potentially exposing systems to code injection and unsafe reflection attacks. This issue arises from missing authorization checks, which may permit unauthorized access to the Nutch REST API. Affected versions range from 1.11 to 1.22. Users are advised to upgrade to version 1.23, which significantly mitigates this risk by removing the Nutch Server component altogether. In cases where upgrading is not feasible, it is critical that access to the Nutch Service is limited to trusted users only to prevent exploitation.

Affected Version(s)

Apache Nutch 1.11 <= 1.22

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Nutch Project Management Committee would like to thank Th1nk for reporting this issue.
.