Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-82439

Apache Storm DRPC: unauthenticated unbounded memory growth

Technology

Apache Storm

CVSS Score

9.8 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

The DRPC server created a request queue the first time it saw a function name and never removed it, so an attacker sending many distinct names grows the heap until the server fails. drpc.authorizer is unset by default, so no credentials are needed. The 9.8 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.