title: Apache IoTDB security advisories description: Security information for Apache IoTDB layout: single

Reporting

Do you want disclose a potential security issue for Apache IoTDB? Send your report to the Apache Security Team.

You can read more about the security policy on:

Advisories

This section is experimental: it provides advisories since 2023 and may lag behind the official CVE publications. It may also lack details found on the project security page linked above. If you have any feedback on how you would like this data to be provided, you are welcome to reach out on our public mailinglist or privately on security@apache.org {.bg-warning}

RPC service denial of service via unchecked Thrift string length ## { #CVE-2026-44630 }

CVE-2026-44630 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-10T09:25:10.202Z

Affected

  • Apache IoTDB before 1.3.8
  • Apache IoTDB from 2.0.0 before 2.0.10

Description

References

Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data ## { #CVE-2026-40454 }

CVE-2026-40454 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-10T07:18:58.462Z

Affected

  • Apache IoTDB C++ client from 1.3.5 before 1.3.8
  • Apache IoTDB C++ client from 2.0.5 before 2.0.10

Description

References

Credits

  • bugbunny.ai (finder)

Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users ## { #CVE-2026-40452 }

CVE-2026-40452 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-10T07:16:03.259Z

Affected

  • Apache IoTDB from 1.3.5 before 1.3.8
  • Apache IoTDB from 2.0.5 before 2.0.10

Description

References

Credits

  • bugbunny.ai (finder)

Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor ## { #CVE-2026-40009 }

CVE-2026-40009 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-10T07:15:02.989Z

Affected

  • Apache IoTDB from 2.0.8 before 2.0.10

Description

References

Credits

  • bugbunny.ai (finder)

Arbitrary Class Instantiation via Pipe Transfer RPC ## { #CVE-2026-40008 }

CVE-2026-40008 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-10T07:13:24.628Z

Affected

  • Apache IoTDB from 1.0.0 before 2.0.10

Description

References

Credits

  • Andrea Cosentino (finder)

Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError ## { #CVE-2026-40007 }

CVE-2026-40007 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-10T07:12:27.092Z

Affected

  • Apache IoTDB from 1.0.0 before 2.0.10

Description

References

Credits

  • bugbunny.ai (finder)

Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver ## { #CVE-2026-40006 }

CVE-2026-40006 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-10T07:10:51.432Z

Affected

  • Apache IoTDB from 1.0.0 before 2.0.10

Description

References

Credits

  • bugbunny.ai (finder)

Path Traversal in Pipe File Transfer Receiver ## { #CVE-2026-40005 }

CVE-2026-40005 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-10T07:09:44.506Z

Affected

  • Apache IoTDB from 1.0.0 before 2.0.10

Description

References

Credits

  • Andrea Cosentino (finder)

REST Basic Authentication Accepts Stale Cached Credentials ## { #CVE-2026-28564 }

CVE-2026-28564 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-10T07:08:01.156Z

Affected

  • Apache IoTDB from 1.0.0 before 2.0.10

Description

References

Credits

JEXL Expression Injection Vulnerability ## { #CVE-2026-24713 }

CVE-2026-24713 [CVE] [CVE json] [OSV json]

Last updated: 2026-03-09T08:59:57.653Z

Affected

  • Apache IoTDB from 1.0.0 before 1.3.7
  • Apache IoTDB from 2.0.0 before 2.0.7

Description

References

Credits

  • Yongzhi Liu of Tencent YunDing Security Lab (finder)

Insecure Default Configuration Vulnerability ## { #CVE-2026-24015 }

CVE-2026-24015 [CVE] [CVE json] [OSV json]

Last updated: 2026-03-09T08:57:43.961Z

Affected

  • Apache IoTDB from 1.0.0 before 1.3.7
  • Apache IoTDB from 2.0.0 before 2.0.7

Description

References

Credits

  • Mapta / BugBunny_ai (finder)

Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write ## { #CVE-2026-24014 }

CVE-2026-24014 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-06T08:34:23.903Z

Affected

  • Apache IoTDB from 1.3.3 before 2.0.8

Description

References

Credits

  • Yan Nan (Detecon Security Lab). (finder)

Authentication Bypass via Forged SessionID in Thrift RPC ## { #CVE-2026-24013 }

CVE-2026-24013 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-06T07:17:46.194Z

Affected

  • Apache IoTDB from 1.3.3 before 2.0.8

Description

References

Credits

  • Yan Nan (Detecon Security Lab) (finder)

Denial of Service via Resource Exhaustion in Aggregation Query ## { #CVE-2026-24012 }

CVE-2026-24012 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-06T07:19:25.470Z

Affected

  • Apache IoTDB from 1.3.3 before 2.0.8

Description

References

Credits

  • Yan Nan (Detecon Security Lab) (finder)

Path Traversal Vulnerability ## { #CVE-2025-64152 }

CVE-2025-64152 [CVE] [CVE json] [OSV json]

Last updated: 2026-06-26T12:16:26.834Z

Affected

  • Apache IoTDB from 1.0.0 before 1.3.6
  • Apache IoTDB from 2.0.0 before 2.0.7

Description

References

Credits

  • Yan Nan (Detecon Security Lab) (finder)

Path Traversal Vulnerability ## { #CVE-2025-55017 }

CVE-2025-55017 [CVE] [CVE json] [OSV json]

Last updated: 2026-06-26T12:15:51.835Z

Affected

  • Apache IoTDB from 2.0.0 before 2.0.6
  • Apache IoTDB from 1.0.0 before 1.3.6

Description

References

Credits

  • qx (finder)

Deserialization of untrusted Data ## { #CVE-2025-48459 }

CVE-2025-48459 [CVE] [CVE json] [OSV json]

Last updated: 2025-09-24T07:57:20.978Z

Affected

  • Apache IoTDB from 1.0.0 before 2.0.5

Description

References

Credits

  • Sanny (finder)
  • 75Acol (finder)
  • stan fang (finder)
  • Wu Jiang (finder)

DoS Vulnerability ## { #CVE-2025-48392 }

CVE-2025-48392 [CVE] [CVE json] [OSV json]

Last updated: 2025-09-24T07:59:48.976Z

Affected

  • Apache IoTDB from 1.3.3 through 1.3.4
  • Apache IoTDB from 2.0.1-beta through 2.0.4

Description

References

Credits

  • yyjLF (finder)

Exposure of Sensitive Information in IoTDB OpenID Authentication ## { #CVE-2025-26864 }

CVE-2025-26864 [CVE] [CVE json] [OSV json]

Last updated: 2025-05-14T10:44:11.661Z

Affected

  • Apache IoTDB from 0.10.0 through 1.3.3
  • Apache IoTDB from 2.0.1-beta before 2.0.2

Description

References

Credits

  • Kyler Katz (finder)

Exposure of Sensitive Information in IoTDB JDBC driver ## { #CVE-2025-26795 }

CVE-2025-26795 [CVE] [CVE json] [OSV json]

Last updated: 2025-05-14T10:43:01.849Z

Affected

  • Apache IoTDB JDBC driver from 0.10.0 through 1.3.3
  • Apache IoTDB JDBC driver from 2.0.1-beta before 2.0.2

Description

References

Credits

  • Kyler Katz (finder)

SSRF Vulnerability (EOL) ## { #CVE-2024-36448 }

CVE-2024-36448 [CVE] [CVE json] [OSV json]

Last updated: 2024-08-05T09:53:35.819Z

Affected

  • Apache IoTDB Workbench from 0.13.0 through *

Description

References

Credits

  • L0ne1y (finder)

Remote Code Execution with untrusted URI of User-defined function ## { #CVE-2024-24780 }

CVE-2024-24780 [CVE] [CVE json] [OSV json]

Last updated: 2025-05-14T10:42:18.799Z

Affected

  • Apache IoTDB from 1.0.0 before 1.3.4

Description

References

Credits

  • Y4 tacker (finder)
  • Nbxiglk (finder)

Unsafe deserialize map in Sync Tool ## { #CVE-2023-51656 }

CVE-2023-51656 [CVE] [CVE json] [OSV json]

Last updated: 2023-12-21T11:47:55.799Z

Affected

  • Apache IoTDB from 0.13.0 through 0.13.4

Description

Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4.Users are recommended to upgrade to version 1.2.2, which fixes the issue.

References

Remote Code Execution (RCE) risk via the UDF ## { #CVE-2023-46226 }

CVE-2023-46226 [CVE] [CVE json] [OSV json]

Last updated: 2024-01-15T10:36:23.883Z

Affected

  • Apache IoTDB from 1.0.0 through 1.2.2

Description

Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2.Users are recommended to upgrade to version 1.3.0, which fixes the issue.

References

Credits

  • Glassy of EagleCloud (finder)

apache/iotdb-web-workbench: forge the JWTToken to access workbench ## { #CVE-2023-30771 }

CVE-2023-30771 [CVE] [CVE json] [OSV json]

Last updated: 2023-04-17T07:26:11.955Z

Affected

  • Apache IoTDB Workbench from 0.13.3 before 0.13.4

Description

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database.

This problem is fixed from version 0.13.4 of iotdb-web-workbench onwards.

References

Apache IoTDB grafana-connector Login Bypass Vulnerability ## { #CVE-2023-24831 }

CVE-2023-24831 [CVE] [CVE json] [OSV json]

Last updated: 2023-04-18T01:31:44.944Z

Affected

  • Apache IoTDB from 0.13.0 through 0.13.3

Description

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3.Attackers could login without authorization. This is fixed in 0.13.4.

References

apache/iotdb-web-workbench: create a user without authorization ## { #CVE-2023-24830 }

CVE-2023-24830 [CVE] [CVE json] [OSV json]

Last updated: 2023-03-08T16:15:22.623Z

Affected

  • Apache IoTDB Workbench from 0.13.0 before 0.13.3

Description

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.

References

apache/iotdb-web-workbench: forge the JWTToken to access workbench ## { #CVE-2023-24829 }

CVE-2023-24829 [CVE] [CVE json] [OSV json]

Last updated: 2023-03-08T16:15:02.969Z

Affected

  • Apache IoTDB Workbench from 0.13.0 before 0.13.3

Description

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 before 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database.

This problem is fixed from version 0.13.3 of iotdb-web-workbench onwards.

References

Apache IoTDB prior to 0.13.3 allows DoS ## { #CVE-2022-43766 }

CVE-2022-43766 [CVE] [CVE json] [OSV json]

Last updated: 2022-10-26T16:04:23.572Z

Affected

  • Apache IoTDB from unspecified through 0.13.2

Description

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.

References

Credits

  • This issue was discovered by 4ra1n of Chaitin Tech

No authorization of DatabaseConnectController in grafana-connector. ## { #CVE-2022-38370 }

CVE-2022-38370 [CVE] [CVE json] [OSV json]

Last updated: 2022-09-05T09:43:12.381Z

Affected

  • Apache IoTDB at 0.13.0

Description

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.

References

Login check vulnerability by session Id ## { #CVE-2022-38369 }

CVE-2022-38369 [CVE] [CVE json] [OSV json]

Last updated: 2022-09-05T09:42:50.630Z

Affected

  • Apache IoTDB at 0.13.0

Description

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

References