Skip to main content

CVE-2026-82427: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Software Foundation Apache Storm Nimbus

0
High
VulnerabilityCVE-2026-82427cvecve-2026-82427cwe-22
Published: 09/14/2026 (09/14/2026, 14:19:16 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache Storm Nimbus

Description

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in both `AsyncLocalizer` and `Container.createBlobstoreLinks`, and the symlink helper force-deletes whatever already exists at the target before creating the link. A submitter could therefore use `../` segments to direct that delete-and-symlink operation at an arbitrary path, as the supervisor user, on every node the topology is scheduled onto. The consequences include recursive deletion of supervisor-owned content and planting a symlink that causes a subsequent worker launch to execute attacker-chosen code as another tenant's operating-system user, which defeats the isolation that `supervisor.run.worker.as.user` is intended to provide. Mitigation Upgrade to 3.1.0, where the resolved target must lie inside the expected root at both call sites. Users who cannot upgrade immediately should restrict topology submission to trusted principals, and may reject submissions whose `topology.blobstore.map` entries contain path separators or `..` segments before they reach Nimbus. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.

Affected software

Apache Software Foundation

Apache Storm Nimbus

Affected versions
>=3.0.0 <3.1.0
Apache Software Foundation/org.apache.storm:storm-server
pkg:maven/Apache Software Foundation/org.apache.storm:storm-server
Affected versions
>=3.0.0 <3.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/14/2026, 14:48:32 UTC

Technical Analysis

The vulnerability arises from improper limitation of pathname to a restricted directory (CWE-22) in Apache Storm Nimbus. Specifically, the topology's 'topology.blobstore.map' allows submitters to choose local names for blobs that are used to build filesystem paths without normalization in AsyncLocalizer and Container.createBlobstoreLinks. This enables attackers to use '../' path traversal sequences to direct deletion and symlink creation operations at arbitrary paths on nodes where the topology runs, as the supervisor user. This can lead to recursive deletion of supervisor-owned content and planting symlinks that cause subsequent worker launches to execute attacker-controlled code as another tenant's OS user, defeating the isolation intended by 'supervisor.run.worker.as.user'. The vulnerability affects versions >=3.0.0 and <3.1.0. The fix in 3.1.0 enforces that resolved paths must lie inside the expected root directory at both vulnerable call sites. As a mitigation, restricting topology submission to trusted principals and rejecting submissions with path separators or '..' segments in 'topology.blobstore.map' entries is recommended for those who cannot upgrade immediately.

Potential Impact

An attacker who can submit topologies can exploit this vulnerability to perform arbitrary file deletions and plant symlinks that lead to execution of attacker-chosen code as other tenants' OS users on every node the topology is scheduled onto. This breaks the intended isolation between tenants and can lead to privilege escalation and compromise of supervisor-owned content.

Mitigation Recommendations

Upgrade Apache Storm Nimbus to version 3.1.0 or later, where the vulnerability is fixed by enforcing path normalization and restricting resolved paths to the expected root directory. If immediate upgrade is not possible, restrict topology submission to trusted principals only and reject any topology submissions whose 'topology.blobstore.map' entries contain path separators or '..' segments before they reach Nimbus.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-08-29T10:07:21.703Z
State
PUBLISHED

Threat ID: 6aa8057055bf5e2cf52f81bc

Added to database: 09/14/2026, 14:32:16 UTC

Last enriched: 09/14/2026, 14:48:32 UTC

Last updated: 09/14/2026, 15:45:25 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses