CVE-2026-82435: CWE-789 Memory allocation with excessive size value in Apache Software Foundation Apache Storm Worker
CVE-2026-82435 is a memory allocation vulnerability in Apache Storm Worker versions 3.0.0 up to but not including 3.1.0. The Netty message decoder processes frames before SASL authentication, allowing an unauthenticated attacker with TCP access to a worker port to trigger large memory allocations based on a length field in the frame. This can cause significant memory pressure or worker instability. The issue is fixed in version 3.1.0 by decoding frames only after handshake completion.
AI Analysis
Technical Summary
The vulnerability exists because the Netty message decoder in Apache Storm Worker runs before SASL authentication handlers in the pipeline, acting on frames from unauthenticated peers. It allocates buffers sized according to a length field in the frame, which can be manipulated to cause excessive memory allocation. Since `storm.messaging.netty.authentication` defaults to false and the decoder precedes the authentication handler, no credentials are required to exploit this. An attacker with TCP reachability to a worker slot port can send a single malicious frame to induce large memory allocations, potentially causing worker instability or denial of service. The default worker heap size is 768 MB, but the exact impact depends on the heap configuration. The issue is resolved in Apache Storm 3.1.0 by ensuring frames are decoded only after the handshake completes.
Potential Impact
An attacker with TCP access to a worker slot port can cause excessive memory allocation on the worker by sending a single crafted frame, potentially leading to worker instability or denial of service due to memory pressure. No authentication is required to exploit this vulnerability. The severity depends on the worker heap size and configuration, with potential for transient or sustained worker loss.
Mitigation Recommendations
Upgrade Apache Storm Worker to version 3.1.0 or later, where the vulnerability is fixed by decoding frames only after handshake completion. For users unable to upgrade immediately, restrict worker slot port access to internal cluster networks only, as recommended by the security model. Additionally, enable `storm.messaging.netty.authentication` if the deployment environment permits, to enforce authentication before frame decoding.
CVE-2026-82435: CWE-789 Memory allocation with excessive size value in Apache Software Foundation Apache Storm Worker
Description
CVE-2026-82435 is a memory allocation vulnerability in Apache Storm Worker versions 3.0.0 up to but not including 3.1.0. The Netty message decoder processes frames before SASL authentication, allowing an unauthenticated attacker with TCP access to a worker port to trigger large memory allocations based on a length field in the frame. This can cause significant memory pressure or worker instability. The issue is fixed in version 3.1.0 by decoding frames only after handshake completion.
Affected software
Apache Software Foundation
Apache Storm Worker
pkg:maven/Apache Software Foundation/org.apache.storm:storm-clientRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists because the Netty message decoder in Apache Storm Worker runs before SASL authentication handlers in the pipeline, acting on frames from unauthenticated peers. It allocates buffers sized according to a length field in the frame, which can be manipulated to cause excessive memory allocation. Since `storm.messaging.netty.authentication` defaults to false and the decoder precedes the authentication handler, no credentials are required to exploit this. An attacker with TCP reachability to a worker slot port can send a single malicious frame to induce large memory allocations, potentially causing worker instability or denial of service. The default worker heap size is 768 MB, but the exact impact depends on the heap configuration. The issue is resolved in Apache Storm 3.1.0 by ensuring frames are decoded only after the handshake completes.
Potential Impact
An attacker with TCP access to a worker slot port can cause excessive memory allocation on the worker by sending a single crafted frame, potentially leading to worker instability or denial of service due to memory pressure. No authentication is required to exploit this vulnerability. The severity depends on the worker heap size and configuration, with potential for transient or sustained worker loss.
Mitigation Recommendations
Upgrade Apache Storm Worker to version 3.1.0 or later, where the vulnerability is fixed by decoding frames only after handshake completion. For users unable to upgrade immediately, restrict worker slot port access to internal cluster networks only, as recommended by the security model. Additionally, enable `storm.messaging.netty.authentication` if the deployment environment permits, to enforce authentication before frame decoding.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-29T10:31:41.545Z
- State
- PUBLISHED
Threat ID: 6aa8057255bf5e2cf52f81ca
Added to database: 09/14/2026, 14:32:18 UTC
Last enriched: 09/14/2026, 14:47:50 UTC
Last updated: 09/14/2026, 18:06:13 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.