VulnSea

org.apache.storm:storm-server vulnerabilities

CVEs whose affected-version data names the org.apache.storm:storm-server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-82434Medium· 6.5⚖ disputed
1w ago

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any ca…

SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.48%via NVD
CVE-2026-82433Medium· 6.5
1w ago

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and t…

SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.42%via NVD
CVE-2026-82432High· 8.1
1w ago

Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only

Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validat…

TwilightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.34%via NVD
CVE-2026-82427High· 7.8
1w ago

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in bo…

TwilightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.17%via NVD
CVE-2026-82426Medium· 6.5
1w ago

Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded

Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded. Th…

SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.51%via NVD
CVE-2026-84179Medium· 6.5
1w ago

Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result without redaction in the topology_conf field of TopologyPageInfo

Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result without redaction in the topology_conf field of TopologyPageInfo. The Storm UI copied that value verb…

SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.42%via NVD
CVE-2026-82441Critical· 9.1
1w ago

Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs

Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on t…

MidnightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.42%via NVD
CVE-2026-82439Critical· 9.8
1w ago

Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen

Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its queue, and the shu…

MidnightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.52%via NVD
org.apache.storm:storm-server vulnerabilities (CVEs) · VulnSea