Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2026-82435
Apache Storm: unauthenticated memory exhaustion in the worker messaging decoder
Technology
Apache Storm
CVSS Score
9.8 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
The worker's Netty message decoder runs ahead of the SASL authentication handlers and allocates buffers sized from a length field in the frame, so a single frame from an unauthenticated peer that can reach a worker slot port can drive a large allocation. storm.messaging.netty.authentication defaults to false. The 9.8 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.