CVE-2026-82434: Apache Storm Nimbus and Client expose topology ZooKeeper credential to read-only users and logs
Apache Storm Nimbus (storm-server) and Client (storm-client) 3.0.0 before 3.1.0 leak the ZooKeeper topology credential to read-only users and to logs; fixed in 3.1.0, with a follow-up post questioning the missing CVSS severity rating.
CVE-2026-82434 affects Apache Storm Nimbus (storm-server) and Apache Storm Client (storm-client) versions 3.0.0 before 3.1.0. When ZooKeeper authentication is configured, Storm retains storm.zookeeper.topology.auth.payload in the topology configuration because workers need it, but Nimbus serves that configuration verbatim to callers holding only read-only access; the credential is also written to logs. The fix is to upgrade to Apache Storm 3.1.0. A follow-up reply on the oss-security disclosure thread by Gabriel Ravier questions whether the CVE was filed without a severity rating or if the CVSS score is simply missing from the listing; that post adds no new technical details, affected versions, or exploitation information. No exploitation or proof of concept has been reported for this issue.
- CVE-2026-82434 affects Apache Storm Nimbus (storm-server) and Apache Storm Client (storm-client) versions 3.0.0 before 3.1.0
- When ZooKeeper authentication is configured, Storm retains storm.zookeeper.topology.auth.payload in the topology configuration because workers need it
- Nimbus serves the topology configuration verbatim to callers holding only read-only access, exposing the credential
- The ZooKeeper topology credential is also written to logs
- Fix: upgrade to Apache Storm 3.1.0
- A follow-up post by Gabriel Ravier on oss-security questions whether the CVE lacks a CVSS severity rating or if it is missing from the listing; no CVSS score is stated in either report
- No exploitation or PoC reported
Coverage timelineoldest first · each row is one article
- · 2d agoCVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs
oss-security· 38
Apache Storm Nimbus and Client expose ZooKeeper topology credentials to read-only users and logs, fixed in 3.1.0.
- · 2d agoRe: CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs
oss-security· 15
Follow-up on oss-security asks why CVE-2026-82434, Apache Storm ZooKeeper credential disclosure to read-only users and logs, lacks a severity rating.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82434 | Apache Storm Leaks ZooKeeper Topology Credential to Read-Only Users and Logs Apache Storm's Nimbus server serves the full topology configuration — including the ZooKeeper credential stored in storm.zookeeper.topology.auth.payload — verbatim to any caller holding only read-only topology permissions, even though that credential is write-capable for the topology's worker heartbeats, backpressure, and error state (it is not a write credential on assignments). The same advisory covers the submission client, which logs the generated payload at INFO on every submission that generates one, and the SASL handlers, which log it at DEBUG, so the secret also reaches log aggregations and support bundles collected from the cluster. A low-privileged user who can merely view a topology, or anyone able to read cluster logs or support bundles, can obtain the credential and forge or delete that topology's worker state. Affected deployments are Apache Storm clusters running versions prior to 3.1.0 with ZooKeeper authentication configured. No public proof-of-concept or in-the-wild exploitation is known and the CVE is not on the CISA KEV list, despite a critical CVSS 4.0 score of 10.0. Do: Upgrade to Apache Storm 3.1.0, where the payload is removed from the configuration served to read-only callers and is no longer written to logs. If you cannot upgrade immediately, rotate storm.zookeeper.topology.auth.payload for all existing topologies, review and scrub retained logs and support bundles for the credential value, and restrict read-only topology permissions to trusted principals only. | 10.0 | — |
| nichelikely on the order of low thousands of cluster deployments worldwide (clearly an estimate) |