Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-82428

Apache Storm: cross-tenant dependency jar substitution through predictable blob keys

Technology

Apache Storm

CVSS Score

8.8 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0, client and cluster

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

Artifacts uploaded with storm jar --artifacts were stored under a key derived only from the Maven coordinate, and an existing blob was silently reused, so the first user to upload under a key controlled the jar every later submitter's workers loaded. The fix is in the submitting client, so every client that uses --artifacts must be upgraded as well as the cluster. The 8.8 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.