title: Apache IoTDB security advisories description: Security information for Apache IoTDB layout: single
Reporting
Do you want disclose a potential security issue for Apache IoTDB? Send your report to the Apache Security Team.
You can read more about the security policy on:
Advisories
This section is experimental: it provides advisories since 2023 and may lag behind the official CVE publications. It may also lack details found on the project security page linked above. If you have any feedback on how you would like this data to be provided, you are welcome to reach out on our public mailinglist or privately on security@apache.org {.bg-warning}
RPC service denial of service via unchecked Thrift string length ## { #CVE-2026-44630 }
CVE-2026-44630 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-10T09:25:10.202Z
Affected
- Apache IoTDB before 1.3.8
- Apache IoTDB from 2.0.0 before 2.0.10
Description
References
Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data ## { #CVE-2026-40454 }
CVE-2026-40454 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-10T07:18:58.462Z
Affected
- Apache IoTDB C++ client from 1.3.5 before 1.3.8
- Apache IoTDB C++ client from 2.0.5 before 2.0.10
Description
References
Credits
Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users ## { #CVE-2026-40452 }
CVE-2026-40452 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-10T07:16:03.259Z
Affected
- Apache IoTDB from 1.3.5 before 1.3.8
- Apache IoTDB from 2.0.5 before 2.0.10
Description
References
Credits
Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor ## { #CVE-2026-40009 }
CVE-2026-40009 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-10T07:15:02.989Z
Affected
- Apache IoTDB from 2.0.8 before 2.0.10
Description
References
Credits
Arbitrary Class Instantiation via Pipe Transfer RPC ## { #CVE-2026-40008 }
CVE-2026-40008 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-10T07:13:24.628Z
Affected
- Apache IoTDB from 1.0.0 before 2.0.10
Description
References
Credits
- Andrea Cosentino (finder)
Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError ## { #CVE-2026-40007 }
CVE-2026-40007 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-10T07:12:27.092Z
Affected
- Apache IoTDB from 1.0.0 before 2.0.10
Description
References
Credits
Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver ## { #CVE-2026-40006 }
CVE-2026-40006 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-10T07:10:51.432Z
Affected
- Apache IoTDB from 1.0.0 before 2.0.10
Description
References
Credits
Path Traversal in Pipe File Transfer Receiver ## { #CVE-2026-40005 }
CVE-2026-40005 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-10T07:09:44.506Z
Affected
- Apache IoTDB from 1.0.0 before 2.0.10
Description
References
Credits
- Andrea Cosentino (finder)
REST Basic Authentication Accepts Stale Cached Credentials ## { #CVE-2026-28564 }
CVE-2026-28564 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-10T07:08:01.156Z
Affected
- Apache IoTDB from 1.0.0 before 2.0.10
Description
References
Credits
JEXL Expression Injection Vulnerability ## { #CVE-2026-24713 }
CVE-2026-24713 [CVE] [CVE json] [OSV json]
Last updated: 2026-03-09T08:59:57.653Z
Affected
- Apache IoTDB from 1.0.0 before 1.3.7
- Apache IoTDB from 2.0.0 before 2.0.7
Description
References
Credits
- Yongzhi Liu of Tencent YunDing Security Lab (finder)
Insecure Default Configuration Vulnerability ## { #CVE-2026-24015 }
CVE-2026-24015 [CVE] [CVE json] [OSV json]
Last updated: 2026-03-09T08:57:43.961Z
Affected
- Apache IoTDB from 1.0.0 before 1.3.7
- Apache IoTDB from 2.0.0 before 2.0.7
Description
References
Credits
- Mapta / BugBunny_ai (finder)
Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write ## { #CVE-2026-24014 }
CVE-2026-24014 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-06T08:34:23.903Z
Affected
- Apache IoTDB from 1.3.3 before 2.0.8
Description
References
Credits
- Yan Nan (Detecon Security Lab). (finder)
Authentication Bypass via Forged SessionID in Thrift RPC ## { #CVE-2026-24013 }
CVE-2026-24013 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-06T07:17:46.194Z
Affected
- Apache IoTDB from 1.3.3 before 2.0.8
Description
References
Credits
- Yan Nan (Detecon Security Lab) (finder)
Denial of Service via Resource Exhaustion in Aggregation Query ## { #CVE-2026-24012 }
CVE-2026-24012 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-06T07:19:25.470Z
Affected
- Apache IoTDB from 1.3.3 before 2.0.8
Description
References
Credits
- Yan Nan (Detecon Security Lab) (finder)
Path Traversal Vulnerability ## { #CVE-2025-64152 }
CVE-2025-64152 [CVE] [CVE json] [OSV json]
Last updated: 2026-06-26T12:16:26.834Z
Affected
- Apache IoTDB from 1.0.0 before 1.3.6
- Apache IoTDB from 2.0.0 before 2.0.7
Description
References
Credits
- Yan Nan (Detecon Security Lab) (finder)
Path Traversal Vulnerability ## { #CVE-2025-55017 }
CVE-2025-55017 [CVE] [CVE json] [OSV json]
Last updated: 2026-06-26T12:15:51.835Z
Affected
- Apache IoTDB from 2.0.0 before 2.0.6
- Apache IoTDB from 1.0.0 before 1.3.6
Description
References
Credits
Deserialization of untrusted Data ## { #CVE-2025-48459 }
CVE-2025-48459 [CVE] [CVE json] [OSV json]
Last updated: 2025-09-24T07:57:20.978Z
Affected
- Apache IoTDB from 1.0.0 before 2.0.5
Description
References
Credits
- Sanny (finder)
- 75Acol (finder)
- stan fang (finder)
- Wu Jiang (finder)
DoS Vulnerability ## { #CVE-2025-48392 }
CVE-2025-48392 [CVE] [CVE json] [OSV json]
Last updated: 2025-09-24T07:59:48.976Z
Affected
- Apache IoTDB from 1.3.3 through 1.3.4
- Apache IoTDB from 2.0.1-beta through 2.0.4
Description
References
Credits
Exposure of Sensitive Information in IoTDB OpenID Authentication ## { #CVE-2025-26864 }
CVE-2025-26864 [CVE] [CVE json] [OSV json]
Last updated: 2025-05-14T10:44:11.661Z
Affected
- Apache IoTDB from 0.10.0 through 1.3.3
- Apache IoTDB from 2.0.1-beta before 2.0.2
Description
References
Credits
Exposure of Sensitive Information in IoTDB JDBC driver ## { #CVE-2025-26795 }
CVE-2025-26795 [CVE] [CVE json] [OSV json]
Last updated: 2025-05-14T10:43:01.849Z
Affected
- Apache IoTDB JDBC driver from 0.10.0 through 1.3.3
- Apache IoTDB JDBC driver from 2.0.1-beta before 2.0.2
Description
References
Credits
SSRF Vulnerability (EOL) ## { #CVE-2024-36448 }
CVE-2024-36448 [CVE] [CVE json] [OSV json]
Last updated: 2024-08-05T09:53:35.819Z
Affected
- Apache IoTDB Workbench from 0.13.0 through *
Description
References
Credits
Remote Code Execution with untrusted URI of User-defined function ## { #CVE-2024-24780 }
CVE-2024-24780 [CVE] [CVE json] [OSV json]
Last updated: 2025-05-14T10:42:18.799Z
Affected
- Apache IoTDB from 1.0.0 before 1.3.4
Description
References
Credits
- Y4 tacker (finder)
- Nbxiglk (finder)
Unsafe deserialize map in Sync Tool ## { #CVE-2023-51656 }
CVE-2023-51656 [CVE] [CVE json] [OSV json]
Last updated: 2023-12-21T11:47:55.799Z
Affected
- Apache IoTDB from 0.13.0 through 0.13.4
Description
Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4.Users are recommended to upgrade to version 1.2.2, which fixes the issue.
References
Remote Code Execution (RCE) risk via the UDF ## { #CVE-2023-46226 }
CVE-2023-46226 [CVE] [CVE json] [OSV json]
Last updated: 2024-01-15T10:36:23.883Z
Affected
- Apache IoTDB from 1.0.0 through 1.2.2
Description
Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2.Users are recommended to upgrade to version 1.3.0, which fixes the issue.
References
Credits
- Glassy of EagleCloud (finder)
apache/iotdb-web-workbench: forge the JWTToken to access workbench ## { #CVE-2023-30771 }
CVE-2023-30771 [CVE] [CVE json] [OSV json]
Last updated: 2023-04-17T07:26:11.955Z
Affected
- Apache IoTDB Workbench from 0.13.3 before 0.13.4
Description
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database.
This problem is fixed from version 0.13.4 of iotdb-web-workbench onwards.
References
Apache IoTDB grafana-connector Login Bypass Vulnerability ## { #CVE-2023-24831 }
CVE-2023-24831 [CVE] [CVE json] [OSV json]
Last updated: 2023-04-18T01:31:44.944Z
Affected
- Apache IoTDB from 0.13.0 through 0.13.3
Description
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3.Attackers could login without authorization. This is fixed in 0.13.4.
References
apache/iotdb-web-workbench: create a user without authorization ## { #CVE-2023-24830 }
CVE-2023-24830 [CVE] [CVE json] [OSV json]
Last updated: 2023-03-08T16:15:22.623Z
Affected
- Apache IoTDB Workbench from 0.13.0 before 0.13.3
Description
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.
References
apache/iotdb-web-workbench: forge the JWTToken to access workbench ## { #CVE-2023-24829 }
CVE-2023-24829 [CVE] [CVE json] [OSV json]
Last updated: 2023-03-08T16:15:02.969Z
Affected
- Apache IoTDB Workbench from 0.13.0 before 0.13.3
Description
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 before 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database.
This problem is fixed from version 0.13.3 of iotdb-web-workbench onwards.
References
Apache IoTDB prior to 0.13.3 allows DoS ## { #CVE-2022-43766 }
CVE-2022-43766 [CVE] [CVE json] [OSV json]
Last updated: 2022-10-26T16:04:23.572Z
Affected
- Apache IoTDB from unspecified through 0.13.2
Description
Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.
References
Credits
- This issue was discovered by 4ra1n of Chaitin Tech
No authorization of DatabaseConnectController in grafana-connector. ## { #CVE-2022-38370 }
CVE-2022-38370 [CVE] [CVE json] [OSV json]
Last updated: 2022-09-05T09:43:12.381Z
Affected
Description
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.
References
Login check vulnerability by session Id ## { #CVE-2022-38369 }
CVE-2022-38369 [CVE] [CVE json] [OSV json]
Last updated: 2022-09-05T09:42:50.630Z
Affected
Description
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
References