As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-82441: Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys
Apache Storm Nimbus versions 3.0.0 before 3.1.0 fail to validate topology dependency keys, allowing an attacker to delete arbitrary blobs belonging to other tenants and disrupt cluster operations. The vulnerability stems from insufficient input validation on the `dependency_jars` and `dependency_artifacts` parameters during topology submission.
Why it matters: Storm operators running affected versions face cross-tenant data loss and denial of service attacks from authenticated users who can manipulate topology submissions to delete blobs outside their scope.
- Source published
- First seen by Cybersecurity Tracker