CVE Explorer
CVE-2026-35565
Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI
Versions Affected: before 2.8.6
Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping values directly into HTML via innerHTML in parseNode() and parseEdge() without sanitization at any layer. An authenticated user with topology submission rights could craft a topology containing malicious HTML/JavaScript in component identifiers
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://repo.maven.apache.org/maven2/","defaultStatus":"unaffected","packageName":"org.apache.storm:storm-webapp","product":"Apache Storm UI","vendor":"Apache Software Foundation","versions":[{"lessThan":"2.8.6","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e852d5d025c1ed869a64fca452f9bf7bb36939db425986fd66503ba7dcbf16b9 · sha256:14e1b79f818bcd38… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e852d5d025c1ed869a64fca452f9bf7bb36939db425986fd66503ba7dcbf16b9 · sha256:14e1b79f818bcd38… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e852d5d025c1ed869a64fca452f9bf7bb36939db425986fd66503ba7dcbf16b9 · sha256:14e1b79f818bcd38… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/04/12/7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e852d5d025c1ed869a64fca452f9bf7bb36939db425986fd66503ba7dcbf16b9 · sha256:14e1b79f818bcd38… · /containers/adp/0/references/0
{"tags":["vendor-advisory"],"url":"https://storm.apache.org/2026/04/12/storm286-released.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e852d5d025c1ed869a64fca452f9bf7bb36939db425986fd66503ba7dcbf16b9 · sha256:14e1b79f818bcd38… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.