Description
Description

The DRPC server kept a map from function name to request queue and created an entry the first time a
function name was seen. No code path ever removed an entry: request cleanup removed the request from its
queue, and the shutdown path drained queues, but the queue object and its map entry remained for the life of
the process.

Function names come from the client and are not constrained to functions any topology has registered, so the
number of retained entries is bounded only by the number of distinct names an attacker chooses to send, and
each retained entry holds the name itself. `drpc.authorizer` is unset by default, so no credentials are
required to reach the endpoint.

The retained state is permanent rather than a transient load spike, so the effect accumulates until the DRPC
server exhausts its heap.

Mitigation

Upgrade to 3.1.0, where a function's queue is removed once nothing is waiting in it.

Users who cannot upgrade immediately should configure `drpc.authorizer` so that only trusted principals can
reach the DRPC endpoints, and should ensure the DRPC ports are not reachable from untrusted networks.

Credit

The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated memory exhaustion (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

The DRPC server in Apache Storm maintains a mapping from client‑supplied function names to request queues, and it never removes entries once they are created. Because the function name comes directly from the requester and the default configuration does not enforce authentication or input validation, an attacker can submit an arbitrary number of distinct names. Each new entry holds the name string and a queue, and the state remains for the lifetime of the Java process. This leads to unbounded memory growth and, over time, can exhaust the JVM heap, causing the DRPC service to crash and interrupt service availability. The weakness is an uncontrolled memory allocation flaw, identified as CWE‑770. No credentials are required to reach the DRPC endpoint; a remote attacker can trigger the exploit by sending crafted requests over the standard DRPC port. The lack of rate limiting or input validation makes the attack trivial; an attacker who continually supplies unique function names will cause steady memory expansion until the heap is exhausted, resulting in a denial of service.

Affected Systems

The vulnerability affects all Apache Storm DRPC releases prior to version 3.1.0. The flaw is present in the core DRPC server logic regardless of the specific topology or custom functions, and the default setup leaves the endpoint unauthenticated unless the drpc.authorizer property is set.

Risk and Exploitability

The lack of rate limiting or input validation makes the attack trivial; an attacker who continually supplies unique function names will cause steady memory expansion until the heap is exhausted, resulting in a denial of service. The CVSS score of 9.8 reflects this high severity. The EPSS score is < 1%, indicating a low but non-zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, indicating no confirmed public exploits yet, but the ease of exploitation and the critical impact raise the overall risk.

Generated by OpenCVE AI on September 21, 2026 at 00:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Storm to version 3.1.0 or newer, which removes empty DRPC queues from the map when no requests are pending.
  • Enable drpc.authorizer and configure it so that only trusted principals can access the DRPC endpoints.
  • Restrict exposure of the DRPC port by placing it behind a firewall or limiting it to trusted networks.

Generated by OpenCVE AI on September 21, 2026 at 00:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its queue, and the shutdown path drained queues, but the queue object and its map entry remained for the life of the process. Function names come from the client and are not constrained to functions any topology has registered, so the number of retained entries is bounded only by the number of distinct names an attacker chooses to send, and each retained entry holds the name itself. `drpc.authorizer` is unset by default, so no credentials are required to reach the endpoint. The retained state is permanent rather than a transient load spike, so the effect accumulates until the DRPC server exhausts its heap. Mitigation Upgrade to 3.1.0, where a function's queue is removed once nothing is waiting in it. Users who cannot upgrade immediately should configure `drpc.authorizer` so that only trusted principals can reach the DRPC endpoints, and should ensure the DRPC ports are not reachable from untrusted networks. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Title Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC
Weaknesses CWE-770
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:51:25.795Z

Reserved: 2026-08-29T10:40:16.365Z

Link: CVE-2026-82439

cve-icon Vulnrichment

Updated: 2026-09-14T14:13:45.333Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:12.470

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-82439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling