Skip to main content

Threats Tagged 'cve-2026-82438'

View all threats tagged with 'cve-2026-82438'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-82438

Threats Tagged 'cve-2026-82438'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-82438 is an origin validation error in Apache Storm Webapp's HTTP components that allows web pages from unrelated origins to read responses intended for authenticated users. The vulnerability arises from three issues: the Logviewer reflecting the Origin header in Access-Control-Allow-Origin with credentials allowed, a misconfigured shared CORS filter permitting credentials, and JSONP wrapping of API responses without an option to disable it. These flaws enable cross-origin reading of cluster, topology, and log data by authenticated operators. The issue is fixed in Apache Storm 3.1.0 by correcting CORS handling and disabling JSONP by default. Users unable to upgrade immediately should use a reverse proxy to strip problematic headers and reject callback parameters.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: cve-2026-82438
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses