CVE-2026-35337
Apache Storm: Kerberos TGT credential deserialized without a class filter
Technology
Apache Storm
CVSS Score
8.8 / 10.0
Affected Versions
Apache Storm before 2.8.6
Upstream Fix
2.8.6
Published
April 13, 2026
OSSeva Coverage
Fixed upstream
Description
When processing topology credentials submitted through the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob with ObjectInputStream.readObject() and no class filtering. An authenticated user with topology submission rights can supply a crafted object and run code in both the Nimbus and worker JVMs. Apache's interim mitigation is an ObjectInputFilter allow-list on ClientAuthUtils.deserializeKerberosTicket(). The 8.8 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm before 2.8.6, you need this patch. Book a discovery call to get covered.