Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-40557

Apache Storm: Prometheus reporter skip_tls_validation disables certificate checks JVM-wide

Technology

Apache Storm

CVSS Score

4.8 / 10.0

Affected Versions

Apache Storm Prometheus Reporter 2.6.3 to before 2.8.7

Upstream Fix

2.8.7

Published

April 27, 2026

OSSeva Coverage

Fixed upstream

Description

When storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation is enabled, which is not the default, the Prometheus reporter calls SSLContext.setDefault() with a trust manager that accepts every certificate. Every later TLS connection in the daemon, including ZooKeeper, Thrift, Netty and UI connections, then trusts any certificate, which allows man-in-the-middle interception. The 4.8 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm Prometheus Reporter 2.6.3 to before 2.8.7, you need this patch. Book a discovery call to get covered.