Impact
A Netty message decoder in Apache Storm Worker processes incoming frames before authentication. The decoder allocates a buffer whose size is taken directly from a length field in the frame. An unauthenticated attacker can send a single frame with a large length value, which then causes the worker to attempt a large memory allocation. This can trigger excessive garbage‑collection pressure or even a crash, effectively denying service to the worker and potentially disrupting the entire cluster. The weakness is a resource‑exhaustion flaw (CWE‑789).
Affected Systems
The flaw is present in Apache Storm Worker deployments with versions prior to 3.1.0, where the default configuration runs the decoder before any authentication handlers. All workers exposing the slot port are vulnerable unless additional protection is applied.
Risk and Exploitability
The CVSS score of 9.8 reflects a high‑impact, unauthenticated, network‑borne attack that can disrupt service. The EPSS score is reported as less than one percent, indicating a very low probability of exploitation in the wild at this time. However, the vulnerability is widely actionable: an attacker only needs TCP reachability to a worker slot port, which is typically open within a cluster. The attack can be performed with a single crafted frame and no special privileges. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment