Cross-Origin Resource Sharing Misconfiguration in Apache Storm's HTTP Components
CVE-2026-82438

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82438?

A misconfiguration in Apache Storm's HTTP components exposes sensitive data by allowing web pages on unrelated origins to access responses intended for authenticated users. The Logviewer inaccurately reflects the 'Origin' header in the 'Access-Control-Allow-Origin' response, combined with 'Access-Control-Allow-Credentials: true', thereby breaching browser security standards. This issue stems from incorrect header configurations in the shared CORS filter and the JSONP wrapping of API responses that permits any origin to bypass same-origin policies. To remediate this vulnerability, users are advised to upgrade to version 3.1.0, which corrects these flawed configurations and introduces options for better control over JSONP access.

Affected Version(s)

Apache Storm Webapp 3.0.0 < 3.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The ASF using Claude Agents
.