org.apache.storm:storm-client
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.storm:storm-clientpage 1 of 1
- CVE-2026-35337HIGHCVSS 8.8EG 8.8✓ Fixed in 2.8.62026-04-13
vulnerable: 2.0.0 ... 2.8.5 (21 versions)
Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob usin…
- CVE-2026-41081MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.8.72026-04-27
vulnerable: 2.0.0 ... 2.8.6 (22 versions)
Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certifica…
Check whether org.apache.storm:storm-client is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.storm:storm-client CVEs against the assets you own.
Start Free Scan →