Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-41870— Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)

Quick assessment

Affected
Apache Software Foundation Apache Nutch
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Nutch 服务器(Nutch REST API)中存在以下漏洞: 缺少授权验证 代码生成控制不当(“代码注入”) 动态管理的代码资源控制不当 使用外部可控输入来选择类或代码(“不安全的反射”) 影响范围: 该问题影响 Apache Nutch 的 1.11 至 1.22 版本。 建议措施: 首选方案:用户建议升级到 1.23 版本,该版本已移除 Nutch 服务器组件。 替代方案:如果无法升级,用户必须限制对运行 Nutch 服务的实例的访问权限,仅允许受信任的用户访问。 同时,请访问 Apache

AI Predicted 7.5 Difficulty: Moderate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-41870

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
Source: CVE Program / CVE List V5
Vulnerability Description
Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.11 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Nutch 1.11 ~ 1.22 -

II. Public POCs for CVE-2026-41870

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-41870

登录查看更多情报信息。

Other References for CVE-2026-41870 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-09 · 9 CVEs total

CVE-2026-74761 Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscripti
CVE-2026-73334 Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that sk
CVE-2026-41871 Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST A
CVE-2026-41869 Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch
CVE-2026-65181 Apache Impala: RCE via External Data Source Class Loading
CVE-2026-57866 Apache Impala: Secrets Exfiltration via SSRF
CVE-2026-56207 Apache Impala: SAML authentication bypass via forged bearer token
CVE-2026-54048 Apache Impala: Avro Schema URL Server-Side Request Forgery

IV. Related Vulnerabilities

V. Comments for CVE-2026-41870

No comments yet


Leave a comment