VulnSea

apache-iotdb vulnerabilities

CVEs whose affected-version data names the apache-iotdb package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-24014Critical· 9.8
2mo ago

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path wit…

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an…

Midnightapache-iotdb · apache-iotdbEPSS 0.69%via OSV
CVE-2026-24013Critical· 9.1
2mo ago

Authentication Bypass by Spoofing vulnerability in Apache IoTDB.

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing open…

Midnightapache-iotdb · apache-iotdbEPSS 0.64%via OSV
CVE-2026-24012High· 7.5
2mo ago

Uncontrolled Resource Consumption vulnerability in Apache IoTDB. 

Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g.…

Twilightapache-iotdb · apache-iotdbEPSS 0.74%via OSV
CVE-2022-38369High· 8.8
4y ago

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

Twilightapache-iotdb · apache-iotdbEPSS 1.2%via OSV
apache-iotdb vulnerabilities (CVEs) · VulnSea