Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2026-82439
Apache Storm DRPC: unauthenticated unbounded memory growth
Technology
Apache Storm
CVSS Score
9.8 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
The DRPC server created a request queue the first time it saw a function name and never removed it, so an attacker sending many distinct names grows the heap until the server fails. drpc.authorizer is unset by default, so no credentials are needed. The 9.8 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.