Known Vulnerabilities for Apache Storm Worker by Apache Software Foundation
Listed below are 7 of the newest known vulnerabilities associated with "Apache Storm Worker" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82437 json | Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemo... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82435 json | Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and ac... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82434 json | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` ... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82430 json | Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire w... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82429 json | Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the ... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82428 json | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Ma... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82427 json | Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor l... | Not Provided | 2026-09-14 | 2026-09-14 |