CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

CVE-2026-82441: Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7170

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-82441: Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys

Apache Storm Nimbus versions 3.0.0 before 3.1.0 fail to validate topology dependency keys, allowing an attacker to delete arbitrary blobs belonging to other tenants and disrupt cluster operations. The vulnerability stems from insufficient input validation on the `dependency_jars` and `dependency_artifacts` parameters during topology submission.

Why it matters: Storm operators running affected versions face cross-tenant data loss and denial of service attacks from authenticated users who can manipulate topology submissions to delete blobs outside their scope.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary