CVE-2026-82441
Apache Storm Nimbus: cross-tenant blob deletion and loss of leadership through dependency keys
Technology
Apache Storm
CVSS Score
9.1 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
Nimbus did not validate the dependency_jars and dependency_artifacts key lists on submission. A submitter could name another topology's blob and have Nimbus delete it during cleanup, or name a key that does not exist, which makes every Nimbus acquire and surrender leadership indefinitely and leaves the cluster unable to schedule. The fix validates new submissions only. The 9.1 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.