CVE-2026-40557
Apache Storm: Prometheus reporter skip_tls_validation disables certificate checks JVM-wide
Technology
Apache Storm
CVSS Score
4.8 / 10.0
Affected Versions
Apache Storm Prometheus Reporter 2.6.3 to before 2.8.7
Upstream Fix
2.8.7
Published
April 27, 2026
OSSeva Coverage
Fixed upstream
Description
When storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation is enabled, which is not the default, the Prometheus reporter calls SSLContext.setDefault() with a trust manager that accepts every certificate. Every later TLS connection in the daemon, including ZooKeeper, Thrift, Netty and UI connections, then trusts any certificate, which allows man-in-the-middle interception. The 4.8 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm Prometheus Reporter 2.6.3 to before 2.8.7, you need this patch. Book a discovery call to get covered.