Back to blog

// OSSeva Blog

Security

Apache Storm Vulnerabilities by Version: CVEs for Storm 1.2, 2.x and 3.x

Matt Reynolds10 min read

The short answer

Storm 3.1.0, released on 12 September 2026, is the only Storm release with every published security fix. It fixed 15 CVEs, all filed against 3.0.0, and its announcement told anyone still on 2.x to treat the same issues as unpatched there, because the 2.x line reached end of life with 2.8.9 on 22 July 2026. Earlier in the year, 2.8.6 and 2.8.7 fixed four CVEs on the 2.x line, among them CVE-2026-35337, a deserialization flaw that lets a user with topology submission rights run code on Nimbus and the workers. The 1.x line has had no release since 1.2.4 in October 2021.

The CVE records for the September batch name 3.0.0 as the affected version and say nothing about 2.x either way. The project's own statement is the one to plan around: a cluster on 2.8.9 should be treated as exposed to the 3.1.0 list, and no 2.x release will fix it.

Storm release lines and their CVEs

Release dates are from the Storm release announcements. Each row lists the CVEs whose ranges include the line, or that the project says to treat as unpatched on it, and that have no fix in its latest release.

LineUpstream statusLatest releaseCVEs with no fix on this lineUpstream fix on this line
3.1Current release; requires Java 253.1.0, 12 September 2026NoneNot applicable
3.0Superseded by 3.13.0.0, 22 July 2026The 15 CVEs fixed in 3.1.0No upstream fix on this line; fixed in 3.1.0
2.8End of life since 22 July 20262.8.9, 22 July 2026, the final 2.x releaseThe 3.1.0 list, which the project says to treat as unpatched on 2.x2.8.6 and 2.8.7 for the four April 2026 CVEs; nothing for the 3.1.0 list
2.6 and 2.7End of life; no release since November 20242.7.1, 28 November 2024; 2.6.4, 3 September 2024CVE-2026-35337, CVE-2026-35565, CVE-2026-41081, CVE-2026-40557 on 2.6.3 and later, and the 3.1.0 listNo upstream fix on these lines
2.4 and 2.5End of life2.5.0, 4 August 2023; 2.4.0, 25 March 2022CVE-2023-43123, CVE-2026-35337, CVE-2026-35565, CVE-2026-41081 and the 3.1.0 listNo upstream fix on these lines
2.0 to 2.3End of life2.3.0, 27 September 2021; 2.2.1, 11 October 2021; 2.1.1, 14 October 2021The same as 2.4 and 2.5; releases before 2.1.1 and 2.2.1 also CVE-2021-38294 and CVE-2021-408652.1.1, 2.2.1 and 2.3.0 for the 2021 CVEs
1.2End of life; the last 1.x release1.2.4, 11 October 2021Possibly the April 2026 CVEs: Apache's records cover every release before 2.8.6 or 2.8.7, while NVD's analysis starts at 2.0.01.2.4 for CVE-2021-38294 and CVE-2021-40865

The 3.1.0 announcement lists 17 advisories. Two of them had no published CVE record when this was checked on 6 October 2026, so they are left out of this guide. For release dates on every line, see the Apache Storm end-of-life chart.

Notable Storm CVEs on 1.2 and 2.x

CVSS is NVD's own score where NVD has scored the record, otherwise the CVSS 3.1 score CISA-ADP added. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.

CVEIssueCVSSAffectedFixed in
CVE-2021-40865The supervisor's worker services deserialize untrusted data before authentication, so a remote attacker can run code9.8 (NVD)1.x before 1.2.4; 2.1.0; 2.2.01.2.4, 2.1.1, 2.2.1, 2.3.0
CVE-2021-38294A crafted Thrift request to the getTopologyHistory service on Nimbus injects shell commands before authentication9.8 (NVD)1.x before 1.2.4; 2.x before 2.2.11.2.4, 2.1.1, 2.2.1, 2.3.0
CVE-2026-35337Nimbus and the workers deserialize the Kerberos TGT credential with no class filter, so a user with submission rights can run code on both8.8 (CISA-ADP)Before 2.8.62.8.6
CVE-2026-41081With TLS on and client certificates optional, the default, a client that presents no valid certificate is given the principal CN=ANONYMOUS instead of being refused6.5 (CISA-ADP)Before 2.8.72.8.7
CVE-2023-43123A temporary file created by storm-core is readable by other local users5.5 (NVD)2.0.0 to 2.5.02.6.0
CVE-2026-35565Topology component IDs and stream names are written into the UI as HTML, so a submitter can plant script that runs in an operator's browser5.4 (CISA-ADP)Before 2.8.62.8.6
CVE-2026-40557Turning on skip_tls_validation for the Prometheus reporter replaces the JVM's default SSL context, so every TLS connection in the daemon stops validating certificates4.8 (CISA-ADP)2.6.3 to 2.8.62.8.7

The two 2021 CVEs are the most serious on the list because neither needs credentials, only network access to Nimbus or a worker port. CVE-2026-35337 needs topology submission rights, but a cluster that leaves nimbus.users unset grants those to every authenticated principal. CVE-2026-41081 matters where an authorizer does not explicitly deny CN=ANONYMOUS, and CVE-2023-43123 only where ui.disable.spout.lag.monitoring has been set to false, since it is true by default.

The 3.1.0 batch

All 15 CVEs give 3.0.0 as the affected version and 3.1.0 as the fix. NVD has not yet scored them, so the score is CISA-ADP's. Apache, as the CNA, scored CVE-2026-82434 at 10.0 under CVSS 4.0 and rated the others important or moderate.

CVEIssueCVSSWhat an attacker needs
CVE-2026-82431SimpleACLAuthorizer ignores nimbus.groups when nimbus.users is empty, so every authenticated principal gets every user-level operation9.8 (CISA-ADP)Any credential, on a cluster restricted by group alone
CVE-2026-82435The worker's Netty decoder sizes buffers from a length field before authentication, so one frame can force a large allocation9.8 (CISA-ADP)TCP access to a worker slot port
CVE-2026-82439The DRPC server keeps a queue for every function name it is sent and never removes them, until the heap runs out9.8 (CISA-ADP)Access to the DRPC port; drpc.authorizer is unset by default
CVE-2026-82441Unvalidated dependency blob keys let a submitter delete another topology's blobs, or leave every Nimbus unable to keep leadership9.1 (CISA-ADP)Topology submission rights
CVE-2026-82428Blob keys for storm jar --artifacts are predictable and reused, so one tenant can replace the dependency jars another tenant's workers load8.8 (CISA-ADP)Blob creation rights on a cluster that uses --artifacts
CVE-2026-82432Rebalance overrides skip the blobstore ACL check that submission applies, and listBlobs returns every key to any caller8.1 (CISA-ADP)Rebalance rights on any topology
CVE-2026-82438Origin reflection in the Logviewer, a misconfigured CORS filter and JSONP responses let other websites read the UI, Logviewer and DRPC APIs as a logged-in user8.1 (CISA-ADP)An authenticated operator visiting a hostile page
CVE-2026-82427Local names in topology.blobstore.map accept ../ segments, so a submitter can delete and symlink paths as the supervisor user7.8 (CISA-ADP)Topology submission rights
CVE-2026-82429A race in the setuid-root worker-launcher lets a tenant redirect its chown and chmod calls at any file on the host7.8 (CISA-ADP)Code running as a topology user with supervisor.run.worker.as.user
CVE-2026-82430The worker-launcher hands the Docker or OCI command file to the tenant before reading it, so the tenant can rewrite the container it starts as root7.8 (CISA-ADP)Code running as a topology user with container isolation
CVE-2026-82426submitTopology accepts any server path as the topology jar, so any file Nimbus can read can be copied out by the submitter6.5 (CISA-ADP)Topology submission rights
CVE-2026-82433getNimbusConf and the UI cluster configuration endpoint return the ZooKeeper auth payload and TLS store passwords unredacted6.5 (CISA-ADP)Any user who passes ui.filter or the user-level Nimbus check
CVE-2026-82434Nimbus serves a topology's write-capable ZooKeeper credential to read-only users, and clients log it6.5 (CISA-ADP); 10.0 (Apache, CVSS 4.0)Read-only topology permission, or access to logs
CVE-2026-84179The topology page merges in the Nimbus daemon configuration without redaction, including the ZooKeeper and TLS secrets6.5 (CISA-ADP)Read-only topology permission
CVE-2026-82437The Logviewer ignores logs.users and logs.groups for daemon logs, and its listing endpoints show every tenant's log files4.3 (CISA-ADP)Any user who passes the Logviewer servlet filter

Read together, the batch is about multi-tenant clusters. Most rows start with a user who can already submit or view a topology and end with that user reading cluster secrets, touching other tenants' topologies or getting root on a supervisor. As the advisory for CVE-2026-82426 points out, a cluster that leaves nimbus.users unset grants submission to every authenticated principal, so the bar is lower than it looks. Three rows need less: CVE-2026-82435 and CVE-2026-82439 need only network access to a worker or DRPC port, and CVE-2026-82431 only a valid credential. Four rows, CVE-2026-82426, CVE-2026-82433, CVE-2026-82434 and CVE-2026-84179, expose the ZooKeeper authentication payload, so the advice in each is to rotate it. The ZooKeeper ensemble under Storm has its own CVE list; see ZooKeeper vulnerabilities by version.

What each line gets

Storm 3.1

3.1.0 carries every fix above. Three of them need more than a server upgrade. The fix for CVE-2026-82428 is in the submitting client, so every machine that runs storm jar --artifacts needs 3.1.0 as well. The worker-launcher must be rebuilt and reinstalled for CVE-2026-82429 and CVE-2026-82430. And a cluster restricted by nimbus.groups alone becomes restrictive for the first time, which will refuse clients outside those groups. JSONP wrapping is also off by default from 3.1.0, behind ui.enable.jsonp.

Storm 3.0

3.0.0 is outside the ranges of the April 2026 CVEs but has all 15 from September. Moving to 3.1.0 keeps the same Java 25 runtime and Java API, so it is a minor upgrade.

Storm 2.8

2.8.6, on 12 April 2026, and 2.8.7, on 25 April, fixed the four 2026 CVEs on 2.x. 2.8.8 and 2.8.9 brought bug fixes and library updates, and 2.8.9 was declared the final 2.x release. The 3.1.0 fixes will not be backported. Moving to 3.x means Java 25 on every Nimbus, supervisor and worker host, and rewriting any Clojure topologies; see upgrading from Storm 2.x to 3.x and Storm 2 end of life.

Storm 2.0 to 2.7

None of these lines has the April 2026 fixes, and the last release of any of them was 2.7.1 in November 2024. 2.0 to 2.5 also lack the CVE-2023-43123 fix from 2.6.0. A cluster still on 2.1.0 or 2.2.0, without 2.1.1 or 2.2.1, is exposed to the two 2021 flaws that need no credentials at all.

Storm 1.2

1.2.4 fixed the 2021 CVEs, and nothing has been released for 1.x since. Whether the April 2026 CVEs reach 1.2 is not settled: Apache's records cover every release before 2.8.6 or 2.8.7, and NVD's analysis starts the range at 2.0.0. Storm 1.2.4 also bundles ZooKeeper 3.4.14, from a ZooKeeper line that has been end of life since 2020; see Storm and ZooKeeper.

What to do on each line

  • 3.0. Move to 3.1.0, upgrade every client that uses --artifacts, rebuild the worker-launcher, and rotate the ZooKeeper authentication payloads and TLS store passwords.
  • 2.8. Plan the Java 25 move to 3.1, or take patched builds from a supplier that backports fixes. Until then, set nimbus.users explicitly, trim topology.readonly.users and topology.readonly.groups, configure drpc.authorizer, enable storm.messaging.netty.authentication, keep Nimbus, worker and DRPC ports inside the cluster, put the UI and Logviewer behind an authenticating reverse proxy that strips CORS headers and rejects callback parameters, and rotate storm.zookeeper.topology.auth.payload.
  • 2.0 to 2.7. 2.8.9 is the only 2.x release with the April 2026 fixes, but it is end of life too, so treat it as a step toward 3.1 or a patched build, not a destination. Apply the 2.8 mitigations in the meantime, and on 2.1.0 or 2.2.0 keep Nimbus and worker ports off every untrusted network.
  • 1.2. Plan the move to 3.1 through a supported path, or take patched builds. Patch or replace the ZooKeeper 3.4 ensemble under it at the same time.

Where OSSeva fits

OSSeva ships patched, signed builds of Apache Storm 1.2 and 2.x, including 2.4, 2.6, 2.7 and 2.8, on the Java version you already run and with topologies unchanged. The bundled ZooKeeper and Curator are patched in the same build, along with transitive dependencies such as Netty, Jetty, Jackson and Kryo, delivered as Maven artifacts, Docker images and tarballs with GPG signatures and VEX statements for scanner findings. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a Nimbus HA, supervisor and ZooKeeper quorum review, an audit of nimbus.users, nimbus.groups and the ZooKeeper credentials, and a topology and dependency inventory against Java 25, and Operate adds 24/7 throughput, latency and back-pressure monitoring with a 15-minute P1 response, a named senior Storm engineer and execution of the Storm 3 and Java 25 migration. See Apache Storm support and Apache Storm extended support.

Tags

Apache StormCVEStorm 2.xStorm 3End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.