Junglewise Threat Intelligence

CVE-2026-82441: Apache Storm Nimbus blobstore validation bypass

CVE-2026-82441 · Severity: critical · CVSS 9.1 · Published 2026-09-14

Technologies: Apache Storm. Vendors: Apache.

Executive brief

Apache Storm's Nimbus cluster manager performs no validation of dependency blob references submitted by topology clients, allowing attackers to delete blobs belonging to other topologies or to cause cluster-wide leadership failures by referencing non-existent blobs. This breaks cluster availability and can lead to data loss of application artifacts.

Technical details

The vulnerability exists in Storm's topology submission handling, where Nimbus accepts but does not validate lists of blobstore keys (`dependency_jars` and `dependency_artifacts`). An attacker can exploit this in two ways: (1) by submitting a topology that references another topology's blob (e.g., its `-stormjar.jar`), causing it to be deleted when the attacker's topology is cleaned up, since Nimbus performs deletions with elevated privileges that bypass ACL checks; (2) by submitting a topology referencing non-existent blobs, causing all Nimbus nodes to enter a leadership thrashing loop where they repeatedly acquire and surrender leadership, leaving the cluster without a leader and unable to schedule or accept new submissions. The attack requires the ability to submit topologies (typically restricted to trusted principals but potentially exploitable in multi-tenant environments). The fix in Storm 3.1.0 validates that all dependency keys are valid blobstore keys and exist before accepting a submission.

Affected products

  • Apache Storm before 3.1.0

Timeline

  • 2026-09-14: disclosed

Related threats