Multiple security vulnerabilities affecting Apache Nutch versions 1.11 through 1.22. The overall risk is high due to unauthenticated remote code execution and job interruption flaws, which can lead to significant data exposure and system compromise.
CVE-2026-41870 (CVSS 9.8 — Critical): An attacker can run commands without logging in by exploiting JEXL injection with unsafe reflection in the Nutch Server REST API.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting Apache Nutch versions 1.11 through 1.22. The overall risk is high due to unauthenticated remote code execution and job interruption flaws, which can lead to significant data exposure and system compromise.
CVE-2026-41870 (CVSS 9.8 — Critical): An attacker can run commands without logging in by exploiting JEXL injection with unsafe reflection in the Nutch Server REST API.[emaillocker id="1283"]
CVE-2026-41871 (CVSS 7.5 — High): The vulnerability enables unauthenticated reflection-based job execution through externally controlled input to select classes.
CVE-2026-41869: Attackers can force a shutdown and interrupt running jobs by exploiting this flaw.
These vulnerabilities collectively present a significant risk to data integrity and system availability.
We recommend you to update Apache Nutch to version 1.23.
The following reports contain further technical details:
[/emaillocker]