Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-35337

Apache Storm: Kerberos TGT credential deserialized without a class filter

Technology

Apache Storm

CVSS Score

8.8 / 10.0

Affected Versions

Apache Storm before 2.8.6

Upstream Fix

2.8.6

Published

April 13, 2026

OSSeva Coverage

Fixed upstream

Description

When processing topology credentials submitted through the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob with ObjectInputStream.readObject() and no class filtering. An authenticated user with topology submission rights can supply a crafted object and run code in both the Nimbus and worker JVMs. Apache's interim mitigation is an ObjectInputFilter allow-list on ClientAuthUtils.deserializeKerberosTicket(). The 8.8 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm before 2.8.6, you need this patch. Book a discovery call to get covered.