org.apache.storm:storm-client
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.storm:storm-clientpage 1 of 1
- CVE-2026-35337HIGHCVSS 8.8EG 8.8fixed in 2.8.62026-04-13
vulnerable: 2.0.0 ... 2.8.5 (21 versions)
Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob usin…
- CVE-2026-41081MEDIUMCVSS 6.5EG 6.5fixed in 2.8.72026-04-27
vulnerable: 2.0.0 ... 2.8.6 (22 versions)
Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certifica…
Check whether org.apache.storm:storm-client is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.storm:storm-client CVEs against the assets you own.
Book a Demo →