CVE-2026-82428
Apache Storm: cross-tenant dependency jar substitution through predictable blob keys
Technology
Apache Storm
CVSS Score
8.8 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0, client and cluster
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
Artifacts uploaded with storm jar --artifacts were stored under a key derived only from the Maven coordinate, and an existing blob was silently reused, so the first user to upload under a key controlled the jar every later submitter's workers loaded. The fix is in the submitting client, so every client that uses --artifacts must be upgraded as well as the cluster. The 8.8 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.