CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

CVE-2026-82435: Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7174

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-82435: Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder

Apache Storm Worker versions 3.0.0 before 3.1.0 contain CVE-2026-82435, which allows unauthenticated remote attackers to exhaust worker memory through the Netty message decoder. The vulnerability exists because the decoder processes frames before Security Assertions Markup Language (SAML) authentication handlers are invoked, enabling an attacker to allocate buffers of arbitrary size from a single frame.

Why it matters: Organizations running Apache Storm 3.0.0 to 3.0.x must upgrade to 3.1.0 or later to prevent denial of service attacks from unauthenticated network-adjacent threat actors targeting worker nodes.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary