Missing Authorization Vulnerability in Apache Nutch Server
CVE-2026-41871
Currently unrated
What is CVE-2026-41871?
A vulnerability in the Apache Nutch Server's REST API allows for missing authorization, enabling attackers to exploit externally-controlled input to select inappropriate classes or code. This issue affects versions of Apache Nutch from 1.10 to 1.22. Users are strongly advised to upgrade to version 1.23, which addresses this vulnerability by removing the Nutch Server component altogether. For those unable to upgrade, it is crucial to limit access to Nutch Service instances strictly to trusted users. For more detailed information, please visit the Apache Nutch security advisories.
Affected Version(s)
Apache Nutch 1.10 <= 1.22