Path Traversal Vulnerability in Apache Storm Blobstore Functionality
CVE-2026-82427

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82427?

A flaw in Apache Storm's blobstore functionality allows users to manipulate file paths without sufficient validation. This vulnerability arises because the topology.blobstore.map parameter enables submitters to define local names for blobs, leading to unsafe path construction in the working directory. Through this, an attacker can exploit the system by using ../ sequences to perform delete-and-symlink operations at arbitrary locations, potentially deleting critical supervisor-owned files or planting symlinks that result in arbitrary code execution as a different operating system user. This compromises the intended isolation mechanisms within the system. To address this vulnerability, users should upgrade to version 3.1.0 or apply workaround measures by restricting topology submissions from untrusted sources.

Affected Version(s)

Apache Storm Nimbus 3.0.0 < 3.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The ASF using Claude Agents
.