Description
Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API).



This issue affects Apache Nutch: from 1.10 through 1.22.



Users are recommended to upgrade to version 1.23, which removes the Nutch Server.
If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only.
Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Published: 2026-09-09
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability originates from missing authorization (CWE‑862) and the use of externally controlled input to select classes via reflection (CWE‑470) in the Nutch REST API. An unauthenticated attacker can send a specially crafted request to the Nutch Server endpoint, causing the server to load and execute attacker‑specified code. This enables full remote code execution on the host, compromising confidentiality, integrity, and availability.

Affected Systems

Apache Nutch versions 1.10 through 1.22 are affected. The flaw resides in the Nutch Server (REST API) component. The advisory recommends upgrading to version 1.23 or newer, which has removed the vulnerable Server.

Risk and Exploitability

The EPSS score is < 1% and the CVSS score is 9.8, yet the vulnerability is not listed in CISA KEV, the lack of authentication together with unsafe reflection provides a direct exploitation path via HTTP. An attacker only needs network access to the REST API endpoint and no credentials. The high potential for arbitrary code execution and the absence of built‑in mitigations make this a high‑risk vulnerability for any exposed Nutch instance. Administrators should treat it as critical and act promptly.

Generated by OpenCVE AI on September 10, 2026 at 23:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Nutch to version 1.23 or later, which removes the vulnerable Nutch Server component.
  • If an upgrade is not possible, restrict network access to the Nutch Server REST API so that only trusted users or systems can reach it, for example by firewalling or IP whitelisting.
  • Disable or remove the Nutch Server component entirely if it is not needed for your deployment.

Generated by OpenCVE AI on September 10, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache nutch
CPEs cpe:2.3:a:apache:nutch:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache nutch

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References

Wed, 09 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Title Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
Weaknesses CWE-470
CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-10T17:56:50.962Z

Reserved: 2026-04-22T06:35:10.384Z

Link: CVE-2026-41871

cve-icon Vulnrichment

Updated: 2026-09-09T11:10:19.289Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T11:17:14.570

Modified: 2026-09-10T20:38:51.250

Link: CVE-2026-41871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:30:12Z

Weaknesses
  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

  • CWE-862

    Missing Authorization