Impact
The DRPC server in Apache Storm maintains a mapping from client‑supplied function names to request queues, and it never removes entries once they are created. Because the function name comes directly from the requester and the default configuration does not enforce authentication or input validation, an attacker can submit an arbitrary number of distinct names. Each new entry holds the name string and a queue, and the state remains for the lifetime of the Java process. This leads to unbounded memory growth and, over time, can exhaust the JVM heap, causing the DRPC service to crash and interrupt service availability. The weakness is an uncontrolled memory allocation flaw, identified as CWE‑770. No credentials are required to reach the DRPC endpoint; a remote attacker can trigger the exploit by sending crafted requests over the standard DRPC port. The lack of rate limiting or input validation makes the attack trivial; an attacker who continually supplies unique function names will cause steady memory expansion until the heap is exhausted, resulting in a denial of service.
Affected Systems
The vulnerability affects all Apache Storm DRPC releases prior to version 3.1.0. The flaw is present in the core DRPC server logic regardless of the specific topology or custom functions, and the default setup leaves the endpoint unauthenticated unless the drpc.authorizer property is set.
Risk and Exploitability
The lack of rate limiting or input validation makes the attack trivial; an attacker who continually supplies unique function names will cause steady memory expansion until the heap is exhausted, resulting in a denial of service. The CVSS score of 9.8 reflects this high severity. The EPSS score is < 1%, indicating a low but non-zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, indicating no confirmed public exploits yet, but the ease of exploitation and the critical impact raise the overall risk.
OpenCVE Enrichment