Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
High7.5CVE-2026-24012 · Published Jul 6, 2026 · updated Jul 8, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-iotdb PyPI | >= 1.3.3, < 2.0.8 | 2.0.8 |
Details and references
Uncontrolled Resource Consumption vulnerability in Apache IoTDB. Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g., a very large time range combined with a minimal interval). This forces the DataNode to build an enormous result set in memory, which exhausts the Java heap and causes the DataNode process to crash. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the CVSS score
- Also known as
- CVE-2026-24012
More iotdb advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 6 | Authentication Bypass by Spoofing vulnerability in Apache IoTDB. CVE-2026-24013Critical9.1fixed in 2.0.8 | Critical9.1 | 2.0.8 |
| Jul 6 | Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to w CVE-2026-24014Critical9.8fixed in 2.0.8 | Critical9.8 | 2.0.8 |
| Sep 242025 | Apache IoTDB: Deserialization of untrusted Data CVE-2025-48459Critical5.3fixed in 2.0.5 | Critical5.3 | 2.0.5 |
| May 142025 | Apache IoTDB Discloses Sensitive Information via Log Files CVE-2025-26864Mediumfixed in 1.3.4, 2.0.2 | Medium | 1.3.4, 2.0.2 |
| May 142025 | Apache IoTDB Vulnerable to Remote Code Execution CVE-2024-24780Critical9.8fixed in 1.3.4 | Critical9.8 | 1.3.4 |
| Jan 152024 | Remote Code Execution vulnerability in Apache IoTDB via UDF CVE-2023-46226High9.8fixed in 1.3.0 | High9.8 | 1.3.0 |