VYPR

Nimbus

by Apache Storm

CVEs (1)

  • CVE-2026-82426Sep 14, 2026
    risk 0.00cvss epss

    Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded. The intended flow is that a client first…