CVE-2026-35337Disclosure(apache / storm)

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch apache storm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.readObject() without any class filtering or validation. An authenticated user with topology submission rights could supply a crafted serialized object in the "TGT" credential field, leading to remote code execution in both the Nimbus and Worker JVMs. Mitigation: 2.x users should upgrade to 2.8.6. Users who cannot upgrade immediately should monkey-patch an ObjectInputFilter allow-list to ClientAuthUtils.deserializeKerberosTicket() restricting deserialized classes to javax.security.auth.kerberos.KerberosTicket and its known dependencies. A guide on how to do this is available in the release notes of 2.8.6. Credit: This issue was discovered by K.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • storm

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
storm

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-13: 4Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-13: 304-13
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets6 URLs
Full discourse4 posts
  • yousukezan@yousukezan
    Disclosure

    リアルタイム処理基盤Apache Stormに深刻な脆弱性が見つかり、認証済みユーザーによる遠隔コード実行や管理者権限の乗っ取りが可能となる恐れが判明した。 Apache Stormのバージョン2.8.6では、2件の脆弱性が修正された。CVE-2026-35337は重要度の高い問題で、storm-clientに影響する。Nimbus Thrift API経由で送信されるKerberosのTGTデータをObjectInputStream.readObject()で検証なしにデシリアライズしていたため、細工されたオブジェクトを使うことでNimbusやWorkerのJVM上で任意コード実行が可能となる。 もう一つのCVE-2026-35565は中程度の問題で、管理UIにおけるXSSである。トポロジーの構成情報をinnerHTMLで直接描画していたため、攻撃者が悪意あるJavaScriptを仕込むと、管理者が画面を閲覧した際にスクリプトが実行される。これによりストアド型XSSや権限昇格が発生する可能性がある。 対策として最新版2.8.6への更新が推奨される。暫定策としては、KerberosTicketのみを許可するフィルタの導入や、UI側でHTMLエスケープ処理を行う必要がある。 https://securityonline.info/apache-storm-vulnerability-rce-xss-cve-2026-35337/

    Post summary

    Apache Storm 2.8.6 is affected by two CVEs—one enabling remote code execution through object deserialization and another causing XSS—and is mitigated by upgrading and applying specific filters or escaping.

    0301051.8K
    14.3K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-35337: Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling https://www.openwall.com/lists/oss-security/2026/04/12/6 CVE-2026-35565: Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI https://www.openwall.com/lists/oss-security/2026/04/12/7

    Post summary

    The text announces two Apache Storm vulnerabilities: CVE‑2026‑35337 allows RCE through unsafe deserialization of Kerberos tokens, and CVE‑2026‑35565 enables stored XSS via unsanitized topology metadata, with links to further details.

    040112866
    4.6K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35337 Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via t… https://www.cve.org/CVERecord?id=CVE-2026-35337

    Post summary

    The post notes a deserialization vulnerability in Apache Storm (versions before 2.8.6) but offers no further details on exploitation, defenses, or false‑positive status.

    0000099
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35337 CVE-2026-35337 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35337 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE-2026-35337 and links to a vulnerability details page and a notification, but provides no additional technical or patch information.

    0000045
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachestorm---

Explore more