org.apache.storm:storm-core vulnerabilities
CVEs whose affected-version data names the org.apache.storm:storm-core package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-82430High· 7.8Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the …
Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the …
▾ TwilightApache Software Foundation · org.apache.storm:storm-coreEPSS 0.14%via NVD
CVE-2026-82429High· 7.8Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid…
Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid…
▾ TwilightApache Software Foundation · org.apache.storm:storm-coreEPSS 0.13%via NVD