CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs
Apache Storm Nimbus and Client expose ZooKeeper topology credentials to read-only users and logs, fixed in 3.1.0.
CVE-2026-82434 affects Apache Storm Nimbus (storm-server) and Storm Client (storm-client) versions 3.0.0 before 3.1.0. When ZooKeeper authentication is configured, Storm retains storm.zookeeper.topology.auth.payload in the topology configuration because workers need it, but Nimbus serves that configuration verbatim to callers holding only read-only access. The credential also leaks into logs.
- ZooKeeper topology auth payload exposed to read-only users
- Credential also written to logs
- Affects storm-server and storm-client 3.0.0 before 3.1.0
- Fix: upgrade to Apache Storm 3.1.0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82434 | Apache Storm Leaks ZooKeeper Topology Credential to Read-Only Users and Logs Apache Storm's Nimbus server serves the full topology configuration — including the ZooKeeper credential stored in storm.zookeeper.topology.auth.payload — verbatim to any caller holding only read-only topology permissions, even though that credential is write-capable for the topology's worker heartbeats, backpressure, and error state (it is not a write credential on assignments). The same advisory covers the submission client, which logs the generated payload at INFO on every submission that generates one, and the SASL handlers, which log it at DEBUG, so the secret also reaches log aggregations and support bundles collected from the cluster. A low-privileged user who can merely view a topology, or anyone able to read cluster logs or support bundles, can obtain the credential and forge or delete that topology's worker state. Affected deployments are Apache Storm clusters running versions prior to 3.1.0 with ZooKeeper authentication configured. No public proof-of-concept or in-the-wild exploitation is known and the CVE is not on the CISA KEV list, despite a critical CVSS 4.0 score of 10.0. Do: Upgrade to Apache Storm 3.1.0, where the payload is removed from the configuration served to read-only callers and is no longer written to logs. If you cannot upgrade immediately, rotate storm.zookeeper.topology.auth.payload for all existing topologies, review and scrub retained logs and support bundles for the credential value, and restrict read-only topology permissions to trusted principals only. | 10.0 | — |
| nichelikely on the order of low thousands of cluster deployments worldwide (clearly an estimate) |
Posted by Richard Zowalla on Sep 13 Severity: Affected versions: - Apache Storm Nimbus (org.apache.storm:storm-server) 3.0.0 before 3.1.0 - Apache Storm Client (org.apache.storm:storm-client) 3.0.0 before 3.1.0 Description: Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any caller holding...
This source does not provide full text. Read it at seclists.org.