CVE Intelligence
Skip to main content
Access Control

CVE-2026-82441

CVE-2026-82441 — Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys

Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on the submission path, yet acts on them in two places. During cleanup of a finished topology, Nimbus deletes the keys named in those lists, and the deletion is performed as the Nimbus subject, for which the blobstore short-circuits its ACL check. A submitter who listed a key belonging to another topology, such as its `-stormjar.jar`, could therefore cause that blob to be deleted when their own topology was cleaned up. Separately, on acquiring leadership a Nimbus compares the dependency keys of all active topologies against the blobstore contents and surrenders leadership if any is missing. A single key that does not exist, on a single active topology, therefore causes every Nimbus to acquire leadership, surrender it and requeue indefinitely, leaving the cluster without a leader and unable to schedule, clean up or accept submissions. Mitigation Upgrade to 3.1.0, where a submission is refused unless every entry in both lists is a dependency blob key and exists in the blobstore. Note that this validates new submissions only; a topology stored by an affected version with an invalid list is unaffected by the upgrade. An operator whose cluster is failing to retain a leader should inspect the Nimbus log for the dependency keys reported as missing and remove or resubmit the topology naming them. Users who cannot upgrade immediately should restrict topology submission to trusted principals. Credit This issue was discovered by rzo1 while investigating an unrelated blobstore defect.

Published Updated Sources: NVD, Apache Software Foundation (CNA), GitHub, GitHub Security Advisory, SOCRadar CTI

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

0%

ahead of 0% of scored CVEs

Affects

Apache

Apache Storm Nimbus

CVSS base

Unscored

no source published a base score

Remediation

The vendor's own words where we have them.

Upgrade Apache Storm Nimbus to a fixed release. Apply vendor patches per advisory and restrict external exposure of the affected component until patched.

First 24 hours

Ordered from the record's own fields — exposure first, because you cannot patch what you have not found.

  • Identify exposed assets running affected vendor/product/version combinations.
  • Prioritize based on EPSS, PoC availability, and external exposure.
  • Search available logs for exploit probes, errors, authentication anomalies, or suspicious child processes matching the vulnerability class.

Affected scope

Vendor, product and version as the advisories word them.

VendorProductVersionsStatus
ApacheApache Storm Nimbus3.0.0 to < 3.1.0Vulnerable

What this weakness leads to

MITRE's own consequences and mitigations for the weakness class — the authority's wording, not guidance derived from the CVSS vector.

MITRE

CWE-639 · Authorization Bypass Through User-Controlled Key

  • Bypass Protection Mechanism
  • Gain Privileges or Assume Identity

Mitigation: For each and every data access, ensure that the user has sufficient privilege to access the record that is being requested.

CWE-20 · Improper Input Validation

  • DoS: Crash, Exit, or Restart
  • DoS: Resource Consumption (CPU)
  • DoS: Resource Consumption (Memory)
  • Read Memory

Mitigation: Consider using language-theoretic security (LangSec) techniques that characterize inputs using a formal language and build recognizers for that language. This effectively requires parsing to be a distinct layer that effectively enforces a boundary between raw input and internal data representations, instead of allowing parser code to be scattered throughout the program, where it could be subject to errors or inconsistencies that create weaknesses. [REF-1109] [REF-1110] [REF-1111]

Weakness & attack patterns

  • CWE-20Improper Input Validation
  • CWE-639

Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.

CAPEC-10 · Buffer Overflow via Environment VariablesCAPEC-101 · Server Side Include (SSI) InjectionCAPEC-104 · Cross Zone ScriptingCAPEC-108 · Command Line Execution through SQL InjectionCAPEC-109 · Object Relational Mapping InjectionCAPEC-110 · SQL Injection through SOAP Parameter TamperingCAPEC-120 · Double EncodingCAPEC-13 · Subverting Environment Variable ValuesCAPEC-135 · Format String InjectionCAPEC-136 · LDAP InjectionCAPEC-14 · Client-side Injection-induced Buffer OverflowCAPEC-153 · Input Data Manipulation
  • T1562.003Impair Defenses: Impair Command History Logging
  • T1574.006Hijack Execution Flow: Dynamic Linker Hijacking
  • T1574.007Hijack Execution Flow: Path Interception by PATH Environment Variable

Timeline

What happened to this CVE, newest first — with the readings a source repeats on a schedule counted underneath rather than listed.

  1. 2026
  2. Initial · CVE published

    Sep 14, 2026 · NVD

  3. Added · GHSA-5978-3w53-3qhw published (unknown)

    Sep 14, 2026 · GitHub Security Advisory

  4. CVE published by MITRE.

    Sep 14, 2026 · SOCRadar CTI

References

4 on the record

Coverage

1 story from the feeds we poll

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.
Answered from this record1

What should defenders know first?

CVE-2026-82441 is Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys, a unscored vulnerability affecting Apache Storm Nimbus from Apache Software Foundation. The current evidence does not list it in CISA KEV, and the exploit status is: Active exploitation is not confirmed from current sources for CVE-2026-82441. Public exploit evidence is: A public PoC is not confirmed from current sources for CVE-2026-82441. The affected-version evidence is listed in the key facts and affected products tables. Defenders should first verify whether exposed or business-critical assets run those versions, then apply vendor patches or mitigations, restrict reachable attack surface, and preserve logs for detection review. CVSS null describes technical severity, while EPSS 0% helps estimate near-term exploit likelihood; neither replaces asset context. Unknown fields should remain explicit in tickets, and threat actor, IOC, victimology, or payload claims should not be added unless a cited source supports them. Monitor CISA KEV, vendor advisories, NVD changes, public PoC repositories, and internal telemetry for update triggers.