Junglewise Threat Intelligence

CVE-2026-35337: Apache Storm remote code execution via unsafe deserialization in Nimbus Thrift API

CVE-2026-35337 · Severity: high · CVSS 8.8 · Published 2026-04-13

Technologies: Apache Storm. Vendors: Maven, Apache.

Executive brief

Apache Storm is a distributed real-time computation system used for processing large volumes of data. A security vulnerability in how the system handles authentication credentials allows an authorized user to execute malicious code on the central management server and worker nodes. This could lead to a complete takeover of the data processing cluster, potentially resulting in data theft or service disruption.

Technical details

A deserialization of untrusted data vulnerability exists in Apache Storm's Nimbus Thrift API. When processing topology credentials, the system uses ObjectInputStream.readObject() to deserialize base64-encoded Ticket Granting Ticket (TGT) blobs without implementing class filtering or validation. An authenticated attacker with topology submission privileges can provide a specially crafted serialized object in the 'TGT' credential field. Successful exploitation results in remote code execution (RCE) within the context of both the Nimbus (master) and Worker JVMs. The issue is resolved in version 2.8.6 by implementing proper deserialization filters.

Affected products

  • Apache Storm Client before 2.8.6

Timeline

  • 2026-04-12: patched: Version 2.8.6 released
  • 2026-04-13: advisory: GitHub and NVD advisories published

References

Related threats