CVE-2022-38369High· 8.8▾ TwilightApache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.1%
1.1% → 1.2%
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
apache-iotdb < 0.13.1Upgrade to a patched release:
apache-iotdb 0.13.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-24014Critical· 9.8Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path wit…
CVE-2026-24013Critical· 9.1Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
CVE-2026-24012High· 7.5Uncontrolled Resource Consumption vulnerability in Apache IoTDB.