Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-35565

Apache Storm UI: stored cross-site scripting through topology metadata

Technology

Apache Storm

CVSS Score

5.4 / 10.0

Affected Versions

Apache Storm before 2.8.6

Upstream Fix

2.8.6

Published

April 13, 2026

OSSeva Coverage

Fixed upstream

Description

The Storm UI visualization writes component IDs, stream names and grouping values into tooltip HTML without escaping. A user with topology submission rights can plant script in those names that runs in the browser of an operator or administrator who views the topology. The 5.4 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm before 2.8.6, you need this patch. Book a discovery call to get covered.