VulnSea

org.apache.storm:storm-client vulnerabilities

CVEs whose affected-version data names the org.apache.storm:storm-client package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-82435Critical· 9.8
1w ago

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried i…

MidnightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.61%via NVD
CVE-2026-82434Medium· 6.5⚖ disputed
1w ago

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any ca…

SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.48%via NVD
CVE-2026-82431Critical· 9.8
1w ago

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.us…

MidnightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.48%via NVD
CVE-2026-82428High· 8.8
1w ago

Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`

Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and pred…

TwilightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.69%via NVD
org.apache.storm:storm-client vulnerabilities (CVEs) · VulnSea