VendorsApachestormany version
Vulnerabilities

Apache Software Foundation Storm any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2021-38294
Shell Command Injection Vulnerability in Nimbus Thrift Server
Published 2021-10-25 · Modified
9.8EPSS 0.845
CVE-2021-40865
Unsafe Pre-Authentication Deserialization In Workers
Published 2021-10-25 · Modified
9.8EPSS 0.656
CVE-2018-11779
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
Published 2019-07-25 · Modified
9.8EPSS 0.035
CVE-2018-1331
In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.
Published 2018-07-10 · Modified
8.8EPSS 0.044
CVE-2026-35337
Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling
Published 2026-04-13 · Analyzed
8.8EPSS 0.010
CVE-2019-0202
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.
Published 2019-07-25 · Modified
7.5EPSS 0.020
CVE-2018-1332
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.
Published 2018-06-05 · Modified
6.5EPSS 0.015
CVE-2026-41081
Apache Storm Client: Anonymous principal assigned on TLS client certificate verification failure
Published 2026-04-27 · Analyzed
6.5EPSS 0.003
CVE-2018-8008
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.
Published 2018-06-05 · Modified
5.8EPSS 0.023
CVE-2023-43123
Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files
Published 2023-11-23 · Modified
5.5EPSS 0.003
CVE-2026-35565
Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI
Published 2026-04-13 · Analyzed
5.4EPSS 0.005