Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/Apache Software Foundation/org.apache.storm:storm-server

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in both `AsyncLocalizer` and `Container.createBlobstoreLinks`, and the symlink helper force-deletes whatever already exists at the target before creating the link. A submitter could therefore use `../` segments to direct that delete-and-symlink operation at an arbitrary path, as the supervisor user, on every node the topology is scheduled onto. The consequences include recursive deletion of supervisor-owned content and planting a symlink that causes a subsequent worker launch to execute attacker-chosen code as another tenant's operating-system user, which defeats the isolation that `supervisor.run.worker.as.user` is intended to provide. Mitigation Upgrade to 3.1.0, where the resolved target must lie inside the expected root at both call sites. Users who cannot upgrade immediately should restrict topology submission to trusted principals, and may reject submissions whose `topology.blobstore.map` entries contain path separators or `..` segments before they reach Nimbus. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.

Join the discussion

CVE-2026-82433 is a vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. The getNimbusConf function returned the full daemon configuration without properly redacting sensitive credentials after only a user-level authorization check. The UI endpoint /api/v1/cluster/configuration lacked proper authorization checks, allowing any user passing the UI filter to access sensitive configuration data including passwords and authentication payloads. This exposure includes ZooKeeper authentication payloads and TLS keystore/truststore passwords. The issue was fixed in version 3.1.0 by masking credential-bearing values and enforcing explicit authorization on all UI API endpoints. Users unable to upgrade immediately should restrict access to the vulnerable endpoint via an authenticating reverse proxy and rotate exposed credentials.

Join the discussion

CVE-2026-82432 is an authorization vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. It allows an authorized user with rebalance privileges to introduce unauthorized blobstore map entries referencing blobs they do not have access to. Additionally, the listBlobs operation lacks authorization checks, exposing metadata about all blobs to any caller able to reach the Nimbus Thrift port. The issue is fixed in version 3.1.0 by enforcing authorization checks on rebalance configuration overrides and listBlobs calls.

Join the discussion

CVE-2026-82434 is a critical vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. When ZooKeeper authentication is enabled, the system exposes the ZooKeeper credential `storm.zookeeper.topology.auth.payload` to users with read-only topology permissions, allowing them to access a credential that grants write capabilities to certain cluster state operations. Additionally, this credential was logged in submission client logs and SASL handlers, potentially exposing it through log aggregation or support bundles. The vulnerability allows unauthorized modification or removal of topology state data related to worker heartbeats, backpressure, and error states. The issue is fixed in version 3.1.0, which removes the credential from configurations served to read-only users and stops logging it.

Join the discussion

CVE-2026-82426 is a path traversal vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. It allows an authenticated user with topology submission rights to submit arbitrary files readable by the Nimbus daemon as their topology jar, bypassing intended upload controls. This can expose sensitive files such as the Nimbus Kerberos keytab, TLS private keys, and ZooKeeper credentials. The vulnerability arises because Nimbus does not verify that the submitted file path is within the designated upload directory. The issue is fixed in version 3.1.0 by enforcing canonicalization and restricting paths to the Nimbus inbox. Mitigations include upgrading to 3.1.0 or restricting submission rights and rotating exposed credentials.

Join the discussion

Apache Storm DRPC versions 3.0.0 up to but not including 3.1.0 have a resource allocation vulnerability where the DRPC server retains a map entry for each unique function name received from clients without ever removing it. Since function names are client-controlled and unrestricted, an attacker can cause the server to exhaust its heap memory by sending many distinct function names. By default, no authorization is required to access the DRPC endpoint, increasing exposure. This issue is fixed in version 3.1.0, which removes function queues when they are empty.

Join the discussion

CVE-2026-82441 is an improper input validation vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. It involves two lists of blobstore keys submitted with topologies that Nimbus does not validate properly. This can lead to unauthorized deletion of blobstore keys belonging to other topologies and cause Nimbus leadership instability, resulting in cluster unavailability. The issue is fixed in version 3.1.0 by validating that all dependency keys exist in the blobstore before accepting submissions.

Join the discussion

CVE-2026-84179 is a vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. It involves insufficient protection of sensitive credentials in the Nimbus API, where the getTopologyPageInfo operation returns merged configuration data including sensitive credentials without redaction. This allows principals with read-only topology access to view sensitive daemon credentials such as ZooKeeper authentication payloads and TLS keystore passwords. The issue is fixed in version 3.1.0 by masking credential-bearing values before serving configuration data.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:maven/Apache Software Foundation/org.apache.storm:storm-server
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses