Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-82435

Apache Storm: unauthenticated memory exhaustion in the worker messaging decoder

Technology

Apache Storm

CVSS Score

9.8 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

The worker's Netty message decoder runs ahead of the SASL authentication handlers and allocates buffers sized from a length field in the frame, so a single frame from an unauthenticated peer that can reach a worker slot port can drive a large allocation. storm.messaging.netty.authentication defaults to false. The 9.8 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.