Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-84179

Apache Storm: unredacted merged daemon configuration through the topology page

Technology

Apache Storm

CVSS Score

6.5 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

getTopologyPageInfo merged the Nimbus daemon configuration into the topology configuration and returned it without redaction, and the UI copied it into GET /api/v1/topology/{id}. A principal with read-only topology permissions could read the ZooKeeper authentication payload and TLS store passwords that getNimbusConf redacts. The 6.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.