Description
Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API).



This issue affects Apache Nutch: from 1.10 through 1.22.



Users are recommended to upgrade to version 1.23, which removes the Nutch Server.
If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only.
Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Published: 2026-09-09
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability involves API that permits an unauthenticated user to command the Nutch Server to shut down or interrupt running jobs. This flaw causes denial of service by rendering the search indexing service unavailable. The weakness is represented by CWE-404 (Improper Resource Closure) and CWE-862 (Missing Authorization). The impact is confined to the Nutch service itself, but interruption of its indexing or search capabilities can affect downstream applications that rely on the service.

Affected Systems

The flaw exists in all supported Apache Nutch releases from version 1.10 through 1.22. The product is the Apache Nutch search platform component managed by the Apache Software Foundation. Upgrade to 1.23, where the Nutch Server component has been removed, eliminates the vulnerability. Systems still running one of the affected versions without monitoring must consider mitigating access restrictions.

Risk and Exploitability

The EPSS score is < 1%, indicating a very low probability of exploitation according to current predictive data. The critical severity, reflecting the potential for complete denial of service to the Nutch Server. The vulnerability is not listed in CISA’s KEV catalog. Because the REST API endpoint is reachable over the network and requires no authentication, any network actor that can reach the API could immediately issue shutdown or interruption commands. The likelihood of exploitation depends on exposure; a publicly reachable instance presents a high risk, while an internally firewalled instance reduces the threat but still allows local attackers to disrupt service. The likely attack vector is unauthenticated remote exploitation of the REST API.

Generated by OpenCVE AI on September 10, 2026 at 23:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Nutch to version 1.23 or later, removing the vulnerable server component.
  • Block external access to the Nutch REST API with firewall or network segmentation to limit exposure.
  • Enable authentication or a reverse proxy that enforces authentication before forwarding requests to the Nutch Server.

Generated by OpenCVE AI on September 10, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache nutch
CPEs cpe:2.3:a:apache:nutch:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache nutch

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References

Wed, 09 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Title Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)
Weaknesses CWE-404
CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-10T18:44:48.446Z

Reserved: 2026-04-22T06:29:48.621Z

Link: CVE-2026-41869

cve-icon Vulnrichment

Updated: 2026-09-10T18:44:37.463Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T11:17:14.290

Modified: 2026-09-10T20:39:59.543

Link: CVE-2026-41869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:30:12Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-862

    Missing Authorization