Description
Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API).



This issue affects Apache Nutch: from 1.11 through 1.22.



Users are recommended to upgrade to version 1.23, which removes the Nutch Server.
If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only.
Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to inject arbitrary JEXL code into the Nutch REST API, leading to execution of arbitrary system commands. Because the API endpoint lacks authentication checks, the flaw can be exploited by any network user with access to the service, granting complete compromise of the host where Nutch runs. The weakness is defined by improper control of dynamically generated code and unsafe reflection, making the impact severe.

Affected Systems

Apache Nutch versions 1.11 through 1.22 are affected. The flaw resides in the Nutch Server component that exposes the REST API for search and indexing functions. Over the same version range, the Nutch Server remains a public-facing service.

Risk and Exploitability

The lack of authentication and ability to inject arbitrary JEXL expressions into the Nutch REST API makes the attack vector the exposed endpoint, allowing a network user to execute arbitrary system commands. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, meaning there is no confirmed public exploitation. Nevertheless, the high CVSS score of 8.8 and the potential for complete system compromise underscore a high severity risk for any machine that exposes the service.

Generated by OpenCVE AI on September 10, 2026 at 23:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Nutch to version 1.23 or later, which removes the vulnerable Nutch Server component.
  • If an upgrade is not possible, restrict network access to the Nutch REST API to trusted users only, for example by using firewalls or VPNs.
  • Continuously monitor the Apache Nutch security advisories for any new patches or updates and apply them promptly.

Generated by OpenCVE AI on September 10, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:nutch:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache nutch
Vendors & Products Apache
Apache nutch

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References

Wed, 09 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.11 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Title Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
Weaknesses CWE-470
CWE-862
CWE-913
CWE-94
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-10T18:03:38.898Z

Reserved: 2026-04-22T06:33:41.605Z

Link: CVE-2026-41870

cve-icon Vulnrichment

Updated: 2026-09-09T11:10:16.941Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T11:17:14.433

Modified: 2026-09-11T13:06:07.280

Link: CVE-2026-41870

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:30:12Z

Weaknesses
  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

  • CWE-862

    Missing Authorization

  • CWE-913

    Improper Control of Dynamically-Managed Code Resources

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')