Missing Authorization Vulnerability in Apache Nutch Server
CVE-2026-41871

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 September 2026

What is CVE-2026-41871?

A vulnerability in the Apache Nutch Server's REST API allows for missing authorization, enabling attackers to exploit externally-controlled input to select inappropriate classes or code. This issue affects versions of Apache Nutch from 1.10 to 1.22. Users are strongly advised to upgrade to version 1.23, which addresses this vulnerability by removing the Nutch Server component altogether. For those unable to upgrade, it is crucial to limit access to Nutch Service instances strictly to trusted users. For more detailed information, please visit the Apache Nutch security advisories.

Affected Version(s)

Apache Nutch 1.10 <= 1.22

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Nutch Project Management Committee would like to thank Th1nk for reporting this issue.
.