← Vulnerability feed

Vulnerability record · CVE-2021-40865 · published 25 October 2021

CVE-2021-40865: Apache Storm supervisor worker unsafe deserialization RCE

Apache · Storm

Apache Storm's supervisor worker services deserialize untrusted data, allowing an unauthenticated attacker to execute arbitrary code. The flaw is rated CVSS 9.8 critical and affects the Storm 1.x, 2.1.x and 2.2.x lines, with fixes in 1.2.4, 2.1.1, 2.2.1 and 2.3.0. Because it is pre-auth and network reachable, any exposed supervisor is at serious risk.

9.8 CVSS 3.1 Critical EPSS 64% · top 0.8% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityPre-auth network RCE with CVSS 9.8 and very high EPSS makes this an urgent patch for any exposed Apache Storm supervisor.

What it is

Apache Storm's supervisor worker services deserialize untrusted data, allowing an unauthenticated attacker to execute arbitrary code. The flaw is rated CVSS 9.8 critical and affects the Storm 1.x, 2.1.x and 2.2.x lines, with fixes in 1.2.4, 2.1.1, 2.2.1 and 2.3.0. Because it is pre-auth and network reachable, any exposed supervisor is at serious risk.

Impact

An attacker gains remote code execution on the supervisor host with the privileges of the Storm service, enabling full compromise of the node and any data or credentials it can reach.

Attack surface

Reached over the network via the supervisor's worker services; the CVSS vector shows no privileges or user interaction required. Any supervisor port exposed beyond a trusted network is a candidate entry point.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is 0.65587 (99.2nd percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Upgrade to the fixed release for your branch: 1.2.4 (1.x), 2.1.1 (2.1.x), 2.2.1 or 2.3.0 (2.2.x).
  • If immediate upgrade is not possible, restrict network access to supervisor and worker ports to trusted hosts only.
  • Place supervisors behind a firewall or VPN and avoid exposing them to the internet.
  • Monitor Apache Storm security advisories for follow-up fixes or backports.
  • Verify the upgrade actually replaced running worker processes, not just the installed package.

Detection

  • Alert on unexpected outbound connections or child processes spawned by Storm supervisor/worker JVMs.
  • Monitor supervisor and worker ports for connections from untrusted source addresses.
  • Look for anomalous deserialization-related errors or crashes in Storm supervisor logs.
  • Baseline normal worker traffic and flag deviations in volume or destination.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-40865 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-38294Apache Storm Nimbus getTopologyHistory pre-auth command injectionApache Storm's Nimbus getTopologyHistory service fails to neutralize input in a Thrift request, allowing OS command injection. The flaw affects Storm…EPSS 84%analysed9.8CVE-2018-11779Apache storm deserialization of untrusted data vulnerabilityIn Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI d…EPSS 3.5%9.8CVE-2015-3188Apache storm permissions and access controls vulnerabilityThe UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 14%8.8CVE-2026-35337Apache storm deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials s…EPSS 1.1%8.8CVE-2018-1331Apache storm vulnerabilityIn Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm c…EPSS 4.4%8.8CVE-2017-9799Apache storm vulnerabilityIt was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for …EPSS 4.9%7.5CVE-2019-0202Apache storm information exposure vulnerabilityThe Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i…EPSS 2.0%7.5CVE-2014-0115Apache storm path traversal vulnerabilityDirectory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the…EPSS 5.3%

Source: NIST National Vulnerability Database (record CVE-2021-40865), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.