CVE-2026-41870: Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API).
This issue affects Apache Nutch: from 1.11 through 1.22.
Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
apache/nutchto a version that resolves this vulnerability.Fixed in 1.23 - Compensating control
If upgrading to Apache Nutch 1.23 is not possible, restrict access to instances running the Nutch Service to trusted users only.
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Nutch versions 1.11 through 1.22 are affected when running the Nutch Server, including its REST API. Version 1.23 removes the Nutch Server.
Does exploitation require authentication?
No. The issue is described as missing authorization and unauthenticated remote code execution through JEXL injection in the Nutch Server REST API.
What should be done if an upgrade cannot be performed immediately?
Restrict access to instances running the Nutch Service to trusted users only. This limits exposure to the unauthenticated REST API attack path.
What is the recommended remediation?
Upgrade to Apache Nutch version 1.23, which removes the Nutch Server.