Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache IoTDB — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in Apache IoTDB, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting Apache IoTDB, a time-series database designed for the Internet of Things, categorized by specific weakness types and tags. It collects disclosed flaws within the software, covering the period from its initial public release through the most recent advisory updates. Readers can use this resource to track the vendor’s official security advisories, understand the prevalence of specific weakness classes within the IoTDB codebase, or review the product’s complete vulnerability history to assess its security posture over time.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-44630 Apache IoTDB: RPC service denial of service via unchecked Thrift string length CWE-789 - - 2026-08-10
CVE-2026-40452 Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users CWE-863 - - 2026-07-10
CVE-2026-40009 Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor CWE-269 - - 2026-07-10
CVE-2026-40008 Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC CWE-470 - - 2026-07-10
CVE-2026-40007 Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError CWE-674 - - 2026-07-10
CVE-2026-40006 Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver CWE-789 - - 2026-07-10
CVE-2026-40005 Apache IoTDB: Path Traversal in Pipe File Transfer Receiver CWE-22 - - 2026-07-10
CVE-2026-28564 Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials CWE-613 - - 2026-07-10
CVE-2026-24013 Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC CWE-290 - - 2026-07-06
CVE-2026-24012 Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query CWE-400 - - 2026-07-06
CVE-2026-24014 Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write CWE-284 - - 2026-07-06
CVE-2025-64152 Apache IoTDB: Path Traversal Vulnerability CWE-22 - - 2026-06-26
CVE-2025-55017 Apache IoTDB: Path Traversal Vulnerability CWE-22 - - 2026-06-26
CVE-2026-24713 Apache IoTDB: JEXL Expression Injection Vulnerability CWE-20 9.1AI Critical AI 2026-03-09
CVE-2026-24015 Apache IoTDB: Insecure Default Configuration Vulnerability CWE-1327 9.1AI Critical AI 2026-03-09
CVE-2025-48392 Apache IoTDB: DoS Vulnerability 9.8AI Critical AI 2025-09-24
CVE-2025-48459 Apache IoTDB: Deserialization of untrusted Data CWE-502 9.8AI Critical AI 2025-09-24
CVE-2025-26864 Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication CWE-200 7.5AI High AI 2025-05-14
CVE-2024-24780 Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function 8.8AI High AI 2025-05-14
CVE-2023-46226 Apache IoTDB: Remote Code Execution (RCE) risk via the UDF 9.8 - 2024-01-15
CVE-2023-51656 Apache IoTDB: Unsafe deserialize map in Sync Tool CWE-502 9.8AI Critical AI 2023-12-21
CVE-2023-24831 Apache IoTDB grafana-connector Login Bypass Vulnerability CWE-287 8.8 - 2023-04-17
CVE-2022-43766 Apache IoTDB prior to 0.13.3 allows DoS 7.5 - 2022-10-26
CVE-2022-38370 No authorization of DatabaseConnectController in grafana-connector. 5.3 - 2022-09-05
CVE-2022-38369 Login check vulnerability by session Id 8.1 - 2022-09-05

All 25 known CVE vulnerabilities affecting Apache IoTDB with full Chinese analysis, references, and POCs where available.