CRITICAL 9.8 NVD

CVE-2026-41871

Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API)

Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .

Affected Products

References

Published: 2026-09-09 · Source: NVD · Feed updated: 2026-09-11
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-09 via NVD. Affected: apache/nutch.

Risk Timeline

CVE Disclosed2026-09-09 · 1 day ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-56207Signature of Bearer token is not verified in last step of SAML2 authentication fCRITICAL9.8
CVE-2026-41869Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerabiCRITICAL9.1
CVE-2026-84939Path traversal vulnerability in Apache FreeMarker template loading mechanism, ifCRITICAL9.1
CVE-2026-41870Missing Authorization, Improper Control of Generation of Code ('Code Injection')HIGH8.8
CVE-2026-57866Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  AuthentiHIGH8.8
CVE-2026-65181Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a clieHIGH8.1
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.