Apache Storm Client
3 known vulnerabilities in Apache Storm Client, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-82434 CVSS 10.0 critical Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the…
- CVE-2026-82431 CVSS 9.8 critical Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before…
- CVE-2026-82428 CVSS 8.8 high Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven…