Vulnerability in Apache Storm's Netty Message Decoder Affects Data Integrity
CVE-2026-82435

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82435?

The vulnerability in Apache Storm's Netty message decoder allows frames to be processed before any authentication occurs, enabling unauthorized buffer allocations from unauthenticated peers. This misconfiguration means that with TCP access to a worker port, an attacker could exploit this to force significant memory allocations, leading to potential operational disruptions. Users are strongly advised to upgrade to version 3.1.0, where frame decoding is properly sequenced after the authentication handshake, or to restrict worker slot port accessibility and enable the storm.messaging.netty.authentication setting in deployments.

Affected Version(s)

Apache Storm Worker 3.0.0 < 3.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The ASF using Claude Agents
.