Memory Allocation with Excessive Size Value Affecting org.apache.storm:storm-client package, versions [3.0.0, 3.1.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.65% (49th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHESTORM-20159141
  • published27 Sept 2026
  • disclosed14 Sept 2026
  • creditThe ASF

Introduced: 14 Sep 2026

NewCVE-2026-82435  (opens in a new tab)
CWE-789  (opens in a new tab)

How to fix?

Upgrade org.apache.storm:storm-client to version 3.1.0 or higher.

Overview

Affected versions of this package are vulnerable to Memory Allocation with Excessive Size Value due to the Netty message decoder processing frames before authentication occurs. An attacker can exhaust system memory by sending a specially crafted frame with a large length field to a worker port, causing excessive buffer allocation.

** Note:** This is only exploitable if the attacker has TCP reachability to the worker slot port and authentication is not enforced.

Workaround

This vulnerability can be mitigated by restricting network access to worker slot ports to only trusted sources within the cluster and enabling storm.messaging.netty.authentication if supported by the deployment.

CVSS Base Scores

version 4.0
version 3.1