Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-82441

Apache Storm Nimbus: cross-tenant blob deletion and loss of leadership through dependency keys

Technology

Apache Storm

CVSS Score

9.1 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

Nimbus did not validate the dependency_jars and dependency_artifacts key lists on submission. A submitter could name another topology's blob and have Nimbus delete it during cleanup, or name a key that does not exist, which makes every Nimbus acquire and surrender leadership indefinitely and leaves the cluster unable to schedule. The fix validates new submissions only. The 9.1 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.