Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-35565
Apache Storm UI: stored cross-site scripting through topology metadata
Technology
Apache Storm
CVSS Score
5.4 / 10.0
Affected Versions
Apache Storm before 2.8.6
Upstream Fix
2.8.6
Published
April 13, 2026
OSSeva Coverage
Fixed upstream
Description
The Storm UI visualization writes component IDs, stream names and grouping values into tooltip HTML without escaping. A user with topology submission rights can plant script in those names that runs in the browser of an operator or administrator who views the topology. The 5.4 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm before 2.8.6, you need this patch. Book a discovery call to get covered.