
Apache Storm CVE-2026-40557: Prometheus Reporter: Disabling TLS verification for Reporter also disables it for all other connections https://www.openwall.com/lists/oss-security/2026/04/25/2 CVE-2026-41081: Client: Anonymous principal assigned on TLS client certificate verification failure https://www.openwall.com/lists/oss-security/2026/04/25/3
Post summary
The message announces two new CVEs affecting Apache Storm, detailing how TLS verification can be bypassed and certificate failures lead to anonymous access. No exploitation evidence, PoC, or patch is mentioned, making this a straightforward disclosure of vulnerability details.


