Apache iotdb
This hub aggregates every CVE we track for Apache iotdb, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
24
CVEs tracked
13
Critical
9
High
0
In CISA KEV
Severity distribution
CRITICAL13HIGH9MEDIUM2
Monthly trend
0
0
0
0
0
0
0
0
2
0
0
0
2
0
0
0
0
0
2
0
0
2
10
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache iotdb.
- CVE-2026-40452Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users7.5
- CVE-2026-40009Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor6.5
- CVE-2026-40008Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC9.8
- CVE-2026-40007Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError7.5
- CVE-2026-40006Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver7.5
- CVE-2026-40005Apache IoTDB: Path Traversal in Pipe File Transfer Receiver9.1
- CVE-2026-28564Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials9.8
- CVE-2026-24013Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC9.1
- CVE-2026-24012Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query7.5
- CVE-2026-24014Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write9.8
- CVE-2025-64152Apache IoTDB: Path Traversal Vulnerability9.1
- CVE-2025-55017Apache IoTDB: Path Traversal Vulnerability9.1
- CVE-2026-24713Apache IoTDB: JEXL Expression Injection Vulnerability9.8
- CVE-2026-24015Apache IoTDB: Insecure Default Configuration Vulnerability9.8
- CVE-2025-48392Apache IoTDB: DoS Vulnerability7.5
Product normalization is registry-driven with AI assist and human review. How it works