Skip to content
iotdbPYSEC-2026-2079

Uncontrolled Resource Consumption vulnerability in Apache IoTDB.

High7.5CVE-2026-24012 · Published Jul 6, 2026 · updated Jul 8, 2026

Source advisory

Affected versions

PackageAffectedFixed in
apache-iotdb
PyPI
>= 1.3.3, < 2.0.82.0.8
Details and references

Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g., a very large time range combined with a minimal interval). This forces the DataNode to build an enormous result set in memory, which exhausts the Java heap and causes the DataNode process to crash. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the CVSS score
Also known as
CVE-2026-24012

More iotdb advisories

All
DateAdvisory
Jul 6Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
CVE-2026-24013Critical9.1fixed in 2.0.8
Jul 6Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to w
CVE-2026-24014Critical9.8fixed in 2.0.8
Sep 242025Apache IoTDB: Deserialization of untrusted Data
CVE-2025-48459Critical5.3fixed in 2.0.5
May 142025Apache IoTDB Discloses Sensitive Information via Log Files
CVE-2025-26864Mediumfixed in 1.3.4, 2.0.2
May 142025Apache IoTDB Vulnerable to Remote Code Execution
CVE-2024-24780Critical9.8fixed in 1.3.4
Jan 152024Remote Code Execution vulnerability in Apache IoTDB via UDF
CVE-2023-46226High9.8fixed in 1.3.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.