Junglewise Threat Intelligence

CVE-2026-82439: Distributed RPC server memory exhaustion via unbounded request queue entries

CVE-2026-82439 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Technologies: Apache Storm. Vendors: Apache.

Executive brief

A Distributed RPC (DRPC) server component that lacks authentication by default retains request queue entries indefinitely, even after requests complete. An unauthenticated attacker can exploit this by sending requests with arbitrary function names, causing the server to accumulate queue entries until heap memory is exhausted, resulting in denial of service.

Technical details

The DRPC server maintains a map associating function names with request queues, creating entries on first sight of a function name. The vulnerability stems from a missing cleanup mechanism: while individual requests are removed from queues and queues are drained on shutdown, the queue objects and their map entries are never deleted during the process lifetime. Since function names originate from untrusted client input and are not validated against registered functions, an attacker can create unbounded entries by sending requests with distinct arbitrary names. No authentication is enforced by default (drpc.authorizer is unset), making the endpoint publicly reachable. This results in permanent memory accumulation that exhausts heap space, causing denial of service. Upgrade to version 3.1.0 or later resolves the issue by removing queue entries once they become empty.

Affected products

  • Apache Storm before 3.1.0

Timeline

  • 2026-09-14: disclosed: CVE-2026-82439 published

References

Related threats