
🚨Critical - Apache Storm ZooKeeper Auth Payload Disclosure (CVE-2026-82434) When ZooKeeper auth is enabled, Apache Storm stores storm.zookeeper.topology.auth.payload in the topology config and Nimbus returns it verbatim to users with read-only topology perms, leaking write-capable ZooKeeper creds. The payload may also be exposed via INFO/DEBUG logs and support bundles, enabling forging/removal of cluster state (heartbeats, backpressure, errors). 👉Affected: org.apache.storm:storm-server, org.apache.storm:storm-client < 3.1.0 | Upgrade to 3.1.0

