CRITICAL 9.1 NVD
CVE-2026-41869
Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutc
Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API).
This issue affects Apache Nutch: from 1.10 through 1.22.
Users are recommended to upgrade to version 1.23, which removes the Nutch Server.
If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only.
Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Affected Products
- apache/nutch
References
- https://lists.apache.org/thread/ps4yhlvo6kdgmksdgb9lv1h4p0oy5fdj
- http://www.openwall.com/lists/oss-security/2026/09/08/3
- https://www.openwall.com/lists/oss-security/2026/09/08/3
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-09-09 via NVD. Affected: apache/nutch.
Risk Timeline
CVE Disclosed2026-09-09 · 2 days ago
Remediation Resources
Official Advisory
www.openwall.com/lists/oss-security/2026/09/08/3Official Advisory
www.openwall.com/lists/oss-security/2026/09/08/3Analysis & PoC
lists.apache.org/thread/ps4yhlvo6kdgmksdgb9lv1h4p0oy5fdjRelated Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-41871 | Missing Authorization, Use of Externally-Controlled Input to Select Classes or C | CRITICAL | 9.8 |
| CVE-2026-56207 | Signature of Bearer token is not verified in last step of SAML2 authentication f | CRITICAL | 9.8 |
| CVE-2026-84939 | Path traversal vulnerability in Apache FreeMarker template loading mechanism, if | CRITICAL | 9.1 |
| CVE-2026-41870 | Missing Authorization, Improper Control of Generation of Code ('Code Injection') | HIGH | 8.8 |
| CVE-2026-57866 | Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenti | HIGH | 8.8 |
| CVE-2026-65181 | Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a clie | HIGH | 8.1 |
vulnfeed aggregates 12842 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.