CVE-2026-82427: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Software Foundation Apache Storm Nimbus
Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in both `AsyncLocalizer` and `Container.createBlobstoreLinks`, and the symlink helper force-deletes whatever already exists at the target before creating the link. A submitter could therefore use `../` segments to direct that delete-and-symlink operation at an arbitrary path, as the supervisor user, on every node the topology is scheduled onto. The consequences include recursive deletion of supervisor-owned content and planting a symlink that causes a subsequent worker launch to execute attacker-chosen code as another tenant's operating-system user, which defeats the isolation that `supervisor.run.worker.as.user` is intended to provide. Mitigation Upgrade to 3.1.0, where the resolved target must lie inside the expected root at both call sites. Users who cannot upgrade immediately should restrict topology submission to trusted principals, and may reject submissions whose `topology.blobstore.map` entries contain path separators or `..` segments before they reach Nimbus. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
AI Analysis
Technical Summary
The vulnerability arises from improper limitation of pathname to a restricted directory (CWE-22) in Apache Storm Nimbus. Specifically, the topology's 'topology.blobstore.map' allows submitters to choose local names for blobs that are used to build filesystem paths without normalization in AsyncLocalizer and Container.createBlobstoreLinks. This enables attackers to use '../' path traversal sequences to direct deletion and symlink creation operations at arbitrary paths on nodes where the topology runs, as the supervisor user. This can lead to recursive deletion of supervisor-owned content and planting symlinks that cause subsequent worker launches to execute attacker-controlled code as another tenant's OS user, defeating the isolation intended by 'supervisor.run.worker.as.user'. The vulnerability affects versions >=3.0.0 and <3.1.0. The fix in 3.1.0 enforces that resolved paths must lie inside the expected root directory at both vulnerable call sites. As a mitigation, restricting topology submission to trusted principals and rejecting submissions with path separators or '..' segments in 'topology.blobstore.map' entries is recommended for those who cannot upgrade immediately.
Potential Impact
An attacker who can submit topologies can exploit this vulnerability to perform arbitrary file deletions and plant symlinks that lead to execution of attacker-chosen code as other tenants' OS users on every node the topology is scheduled onto. This breaks the intended isolation between tenants and can lead to privilege escalation and compromise of supervisor-owned content.
Mitigation Recommendations
Upgrade Apache Storm Nimbus to version 3.1.0 or later, where the vulnerability is fixed by enforcing path normalization and restricting resolved paths to the expected root directory. If immediate upgrade is not possible, restrict topology submission to trusted principals only and reject any topology submissions whose 'topology.blobstore.map' entries contain path separators or '..' segments before they reach Nimbus.
CVE-2026-82427: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Software Foundation Apache Storm Nimbus
Description
Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in both `AsyncLocalizer` and `Container.createBlobstoreLinks`, and the symlink helper force-deletes whatever already exists at the target before creating the link. A submitter could therefore use `../` segments to direct that delete-and-symlink operation at an arbitrary path, as the supervisor user, on every node the topology is scheduled onto. The consequences include recursive deletion of supervisor-owned content and planting a symlink that causes a subsequent worker launch to execute attacker-chosen code as another tenant's operating-system user, which defeats the isolation that `supervisor.run.worker.as.user` is intended to provide. Mitigation Upgrade to 3.1.0, where the resolved target must lie inside the expected root at both call sites. Users who cannot upgrade immediately should restrict topology submission to trusted principals, and may reject submissions whose `topology.blobstore.map` entries contain path separators or `..` segments before they reach Nimbus. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Affected software
Apache Software Foundation
Apache Storm Nimbus
pkg:maven/Apache Software Foundation/org.apache.storm:storm-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from improper limitation of pathname to a restricted directory (CWE-22) in Apache Storm Nimbus. Specifically, the topology's 'topology.blobstore.map' allows submitters to choose local names for blobs that are used to build filesystem paths without normalization in AsyncLocalizer and Container.createBlobstoreLinks. This enables attackers to use '../' path traversal sequences to direct deletion and symlink creation operations at arbitrary paths on nodes where the topology runs, as the supervisor user. This can lead to recursive deletion of supervisor-owned content and planting symlinks that cause subsequent worker launches to execute attacker-controlled code as another tenant's OS user, defeating the isolation intended by 'supervisor.run.worker.as.user'. The vulnerability affects versions >=3.0.0 and <3.1.0. The fix in 3.1.0 enforces that resolved paths must lie inside the expected root directory at both vulnerable call sites. As a mitigation, restricting topology submission to trusted principals and rejecting submissions with path separators or '..' segments in 'topology.blobstore.map' entries is recommended for those who cannot upgrade immediately.
Potential Impact
An attacker who can submit topologies can exploit this vulnerability to perform arbitrary file deletions and plant symlinks that lead to execution of attacker-chosen code as other tenants' OS users on every node the topology is scheduled onto. This breaks the intended isolation between tenants and can lead to privilege escalation and compromise of supervisor-owned content.
Mitigation Recommendations
Upgrade Apache Storm Nimbus to version 3.1.0 or later, where the vulnerability is fixed by enforcing path normalization and restricting resolved paths to the expected root directory. If immediate upgrade is not possible, restrict topology submission to trusted principals only and reject any topology submissions whose 'topology.blobstore.map' entries contain path separators or '..' segments before they reach Nimbus.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-29T10:07:21.703Z
- State
- PUBLISHED
Threat ID: 6aa8057055bf5e2cf52f81bc
Added to database: 09/14/2026, 14:32:16 UTC
Last enriched: 09/14/2026, 14:48:32 UTC
Last updated: 09/14/2026, 15:45:25 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.