As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-82435: Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder
Apache Storm Worker versions 3.0.0 before 3.1.0 contain CVE-2026-82435, which allows unauthenticated remote attackers to exhaust worker memory through the Netty message decoder. The vulnerability exists because the decoder processes frames before Security Assertions Markup Language (SAML) authentication handlers are invoked, enabling an attacker to allocate buffers of arbitrary size from a single frame.
Why it matters: Organizations running Apache Storm 3.0.0 to 3.0.x must upgrade to 3.1.0 or later to prevent denial of service attacks from unauthenticated network-adjacent threat actors targeting worker nodes.
- Source published
- First seen by Cybersecurity Tracker