CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

CVE-2026-82439: Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7171

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-82439: Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC

Apache Storm DRPC (Distributed Remote Procedure Call) server versions 3.0.0 before 3.1.0 contain a memory leak vulnerability where request queues accumulate indefinitely without cleanup. An unauthenticated attacker can trigger unbounded memory growth by repeatedly sending requests with varying function names, eventually causing denial of service through resource exhaustion.

Why it matters: Organizations running Apache Storm 3.0.0 for DRPC operations face availability risk from remote attackers who can exhaust server memory without credentials; upgrading to version 3.1.0 or later is required.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary