CRITICAL 9.8 NVD
CVE-2026-41871
Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API)
Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API).
This issue affects Apache Nutch: from 1.10 through 1.22.
Users are recommended to upgrade to version 1.23, which removes the Nutch Server.
If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only.
Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Affected Products
- apache/nutch
References
- https://lists.apache.org/thread/rbr63fx8vlrhzrfknq2l0mg0d0blsl54
- http://www.openwall.com/lists/oss-security/2026/09/08/5
- https://www.openwall.com/lists/oss-security/2026/09/08/5
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-09 via NVD. Affected: apache/nutch.
Risk Timeline
CVE Disclosed2026-09-09 · 1 day ago
Remediation Resources
Official Advisory
www.openwall.com/lists/oss-security/2026/09/08/5Official Advisory
www.openwall.com/lists/oss-security/2026/09/08/5Analysis & PoC
lists.apache.org/thread/rbr63fx8vlrhzrfknq2l0mg0d0blsl54Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-56207 | Signature of Bearer token is not verified in last step of SAML2 authentication f | CRITICAL | 9.8 |
| CVE-2026-41869 | Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerabi | CRITICAL | 9.1 |
| CVE-2026-84939 | Path traversal vulnerability in Apache FreeMarker template loading mechanism, if | CRITICAL | 9.1 |
| CVE-2026-41870 | Missing Authorization, Improper Control of Generation of Code ('Code Injection') | HIGH | 8.8 |
| CVE-2026-57866 | Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenti | HIGH | 8.8 |
| CVE-2026-65181 | Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a clie | HIGH | 8.1 |
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.