CVE-2026-40557Disclosure(apache / storm_prometheus_reporter)

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description:  In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it is disabled) intending to affect only the Prometheus reporter, the undocumented global side effect creates an attack surface across every TLS-protected communication channel in the Storm daemon. The PrometheusPreparableReporter class implements an INSECURE_TRUST_MANAGER that accepts all SSL certificates without validation, with empty checkClientTrusted and checkServerTrusted methods. Most critically, when the storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation configuration option is enabled (default = disabled) for HTTPS Prometheus PushGateway connections, the INSECURE_CONNECTION_FACTORY calls SSLContext.setDefault(sslContext), which globally replaces the JVM's default SSL context rather than applying the insecure context only to the Prometheus connection. This payload flows through storm.yaml configuration → PrometheusPreparableReporter.prepare() → INSECURE_CONNECTION_FACTORY → SSLContext.setDefault(), resulting in a JVM-wide TLS security downgrade. All subsequent HTTPS connections in the process - including ZooKeeper, Thrift, Netty, and UI connections - silently trust all certificates, including self-signed, expired, and attacker-generated ones, enabling man-in-the-middle interception of cluster state, topology submissions, tuple data, and administrative credentials. Mitigation: 2.x users should upgrade to 2.8.7 if the Prometheus Metrics Reporter is used. Prometheus Metrics Reporter Users who cannot upgrade immediately should remove the storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation: true setting from their storm.yaml configuration and instead configure a proper truststore containing the PushGateway's certificate.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • storm_prometheus_reporter

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
storm_prometheus_reporter

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-25: 1Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-28: 104-2504-2704-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-251
General1
2026-04-271
Disclosure1
2026-04-281
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Storm CVE-2026-40557: Prometheus Reporter: Disabling TLS verification for Reporter also disables it for all other connections https://www.openwall.com/lists/oss-security/2026/04/25/2 CVE-2026-41081: Client: Anonymous principal assigned on TLS client certificate verification failure https://www.openwall.com/lists/oss-security/2026/04/25/3

    Post summary

    The text announces two Apache Storm CVEs, detailing TLS verification-related weaknesses, but does not provide PoC, exploit code, active exploitation evidence, or patch information.

    02072569
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40557 Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description:  In prod… https://www.cve.org/CVERecord?id=CVE-2026-40557

    Post summary

    A new vulnerability, CVE-2026-40557, has been disclosed affecting Apache Storm Prometheus Reporter versions 2.6.3 through 2.8.6, involving improper certificate validation due to a global SSL context downgrade.

    0000086
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40557 CVE-2026-40557 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40557 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The content merely announces CVE-2026-40557 with links to vulnerability details and a notification, but provides no technical, PoC, exploit, or patch information.

    0000042
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachestorm_prometheus_reporter---

Explore more