Skip to content
iotdbGHSA-g6hg-4v3c-6jq7

Apache IoTDB subject to ReDOS with Java 8

High7.5CVE-2022-43766 · Published Oct 26, 2022 · updated Jun 9, 2026

Apache IoTDB versions 0.12.2 through 0.12.6, and 0.13.0 through 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. This issue is patched in 0.13.3. Users should upgrade or use a later version of Java to avoid it.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-iotdb
PyPI
>= 0.12.2, < 0.13.30.13.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400
Also known as
CVE-2022-43766, PYSEC-2022-42972

More iotdb advisories

All iotdb
Advisory
Remote Code Execution vulnerability in Apache IoTDB via UDF
High9.8Jan 15, 2024
Apache IoTDB Grafana Connector vulnerable to Improper Authentication
Critical9.8Apr 17, 2023
iotdb: improper authorization
UnratedApr 17, 2023
iotdb: improper authorization
UnratedJan 31, 2023
iotdb: improper authentication
UnratedJan 30, 2023
Apache IoTDB Session Fixation vulnerability
Medium8.8Sep 6, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.