ZeroHour
Story · 1 source · 2 articlesfirst updated ()6· 2 reads

CVE-2026-82434: Apache Storm Nimbus and Client expose topology ZooKeeper credential to read-only users and logs

mediumVulnerabilityimportance 38CVE-2026-82434
What's new: A second report is a mailing-list follow-up to the original disclosure asking why CVE-2026-82434 has no listed severity rating; it adds no new technical details, affected versions, or exploitation information beyond the original disclosure.
Merged summary · glm-5.3 · rewritten as coverage arrives

Apache Storm Nimbus (storm-server) and Client (storm-client) 3.0.0 before 3.1.0 leak the ZooKeeper topology credential to read-only users and to logs; fixed in 3.1.0, with a follow-up post questioning the missing CVSS severity rating.

CVE-2026-82434 affects Apache Storm Nimbus (storm-server) and Apache Storm Client (storm-client) versions 3.0.0 before 3.1.0. When ZooKeeper authentication is configured, Storm retains storm.zookeeper.topology.auth.payload in the topology configuration because workers need it, but Nimbus serves that configuration verbatim to callers holding only read-only access; the credential is also written to logs. The fix is to upgrade to Apache Storm 3.1.0. A follow-up reply on the oss-security disclosure thread by Gabriel Ravier questions whether the CVE was filed without a severity rating or if the CVSS score is simply missing from the listing; that post adds no new technical details, affected versions, or exploitation information. No exploitation or proof of concept has been reported for this issue.

  • CVE-2026-82434 affects Apache Storm Nimbus (storm-server) and Apache Storm Client (storm-client) versions 3.0.0 before 3.1.0
  • When ZooKeeper authentication is configured, Storm retains storm.zookeeper.topology.auth.payload in the topology configuration because workers need it
  • Nimbus serves the topology configuration verbatim to callers holding only read-only access, exposing the credential
  • The ZooKeeper topology credential is also written to logs
  • Fix: upgrade to Apache Storm 3.1.0
  • A follow-up post by Gabriel Ravier on oss-security questions whether the CVE lacks a CVSS severity rating or if it is missing from the listing; no CVSS score is stated in either report
  • No exploitation or PoC reported

Coverage timeline

  1. · 2d ago
    oss-security· 38
    CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs

    Apache Storm Nimbus and Client expose ZooKeeper topology credentials to read-only users and logs, fixed in 3.1.0.

  2. · 2d ago
    oss-security· 15
    Re: CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs

    Follow-up on oss-security asks why CVE-2026-82434, Apache Storm ZooKeeper credential disclosure to read-only users and logs, lacks a severity rating.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82434
Apache Storm Leaks ZooKeeper Topology Credential to Read-Only Users and Logs

Apache Storm's Nimbus server serves the full topology configuration — including the ZooKeeper credential stored in storm.zookeeper.topology.auth.payload — verbatim to any caller holding only read-only topology permissions, even though that credential is write-capable for the topology's worker heartbeats, backpressure, and error state (it is not a write credential on assignments). The same advisory covers the submission client, which logs the generated payload at INFO on every submission that generates one, and the SASL handlers, which log it at DEBUG, so the secret also reaches log aggregations and support bundles collected from the cluster. A low-privileged user who can merely view a topology, or anyone able to read cluster logs or support bundles, can obtain the credential and forge or delete that topology's worker state. Affected deployments are Apache Storm clusters running versions prior to 3.1.0 with ZooKeeper authentication configured. No public proof-of-concept or in-the-wild exploitation is known and the CVE is not on the CISA KEV list, despite a critical CVSS 4.0 score of 10.0.

Do: Upgrade to Apache Storm 3.1.0, where the payload is removed from the configuration served to read-only callers and is no longer written to logs. If you cannot upgrade immediately, rotate storm.zookeeper.topology.auth.payload for all existing topologies, review and scrub retained logs and support bundles for the credential value, and restrict read-only topology permissions to trusted principals only.

10.0
  • Apache Software Foundation Apache Storm (Nimbus) versions prior to 3.1.0
  • Apache Software Foundation Apache Storm Client (submission client and SASL handlers) versions prior to 3.1.0
nichelikely on the order of low thousands of cluster deployments worldwide (clearly an estimate)