{"id":"GHSA-jf89-3q6q-vcgr","summary":"Apache Storm: Deserialization of Untrusted Data vulnerability","details":"Deserialization of Untrusted Data vulnerability in Apache Storm.\n\nVersions Affected:\nbefore 2.8.6.\n\n\nDescription:\nWhen processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.readObject() without any class filtering or validation. An authenticated user with topology submission rights could supply a crafted serialized object in the \"TGT\" credential field, leading to remote code execution in both the Nimbus and Worker JVMs.\n\n\nMitigation:\n2.x users should upgrade to 2.8.6.\n\n\nUsers who cannot upgrade immediately should monkey-patch an ObjectInputFilter allow-list to ClientAuthUtils.deserializeKerberosTicket() restricting deserialized classes to javax.security.auth.kerberos.KerberosTicket and its known dependencies. A guide on how to do this is available in the release notes of 2.8.6.\n\nCredit: This issue was discovered by K.","aliases":["CVE-2026-35337"],"modified":"2026-04-14T23:11:26.035032Z","published":"2026-04-13T12:31:15Z","database_specific":{"cwe_ids":["CWE-502"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-14T22:51:32Z","nvd_published_at":"2026-04-13T10:16:11Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35337"},{"type":"PACKAGE","url":"https://github.com/apache/storm"},{"type":"WEB","url":"https://storm.apache.org/2026/04/12/storm286-released.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/12/6"}],"affected":[{"package":{"name":"org.apache.storm:storm-client","ecosystem":"Maven","purl":"pkg:maven/org.apache.storm/storm-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.6"}]}],"versions":["2.0.0","2.1.0","2.1.1","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.7.0","2.7.1","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4","2.8.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jf89-3q6q-vcgr/GHSA-jf89-3q6q-vcgr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}