Threats Tagged 'cve-2026-82438'
View all threats tagged with 'cve-2026-82438'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-82438'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-82438 is an origin validation error in Apache Storm Webapp's HTTP components that allows web pages from unrelated origins to read responses intended for authenticated users. The vulnerability arises from three issues: the Logviewer reflecting the Origin header in Access-Control-Allow-Origin with credentials allowed, a misconfigured shared CORS filter permitting credentials, and JSONP wrapping of API responses without an option to disable it. These flaws enable cross-origin reading of cluster, topology, and log data by authenticated operators. The issue is fixed in Apache Storm 3.1.0 by correcting CORS handling and disabling JSONP by default. Users unable to upgrade immediately should use a reverse proxy to strip problematic headers and reject callback parameters. Join the discussion | CVE Database V5 | 09/14/2026, 14:02:07 UTC Added: 09/14/2026, 14:32:18 UTC |
Showing 1 to 1 of 1 result