Vulnerability in Apache Storm's Nimbus Component Affecting Blobstore Operations
CVE-2026-82441

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82441?

An improper input validation vulnerability exists in the Nimbus component of Apache Storm, where submitted topology lists dependency_jars and dependency_artifacts are not validated, allowing a malicious actor to manipulate blobstore operations. Specifically, during the cleanup of topologies, Nimbus may delete blobstore keys not intended for the submitted topology, causing potential data loss. Moreover, if a dependency key is missing during leadership election, it can trigger an endless leadership acquisition cycle, leaving the cluster inoperative. To mitigate this, users should upgrade to version 3.1.0, which enforces strict validation of dependency keys, thus preventing this exploitation path.

Affected Version(s)

Apache Storm Nimbus 3.0.0 < 3.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rzo1
.