Apache Storm Nimbus
7 known vulnerabilities in Apache Storm Nimbus, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-82434 CVSS 10.0 critical Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the…
- CVE-2026-82433 CVSS 6.5 medium Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check…
- CVE-2026-82432 CVSS 8.1 high Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts…
- CVE-2026-82427 CVSS 7.8 high Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That…
- CVE-2026-82426 CVSS 6.5 medium Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and…
- CVE-2026-84179 CVSS 6.5 medium Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result…
- CVE-2026-82441 CVSS 9.1 critical Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills…