VulnSea

apache-iotdb has 4 CVEs on record between 2022 and 2026. 3 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 8.9 (high), with 2 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.9
Publish → KEV
Last 90 days
3 prev 0

Products

  • apache-iotdb 4
4
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

apache-iotdb vulnerabilities

CVEs affecting apache-iotdb, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-24014Critical· 9.8
2mo ago

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path wit…

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an…

Midnightapache-iotdb · apache-iotdbEPSS 0.69%via OSV
CVE-2026-24013Critical· 9.1
2mo ago

Authentication Bypass by Spoofing vulnerability in Apache IoTDB.

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing open…

Midnightapache-iotdb · apache-iotdbEPSS 0.64%via OSV
CVE-2026-24012High· 7.5
2mo ago

Uncontrolled Resource Consumption vulnerability in Apache IoTDB. 

Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g.…

Twilightapache-iotdb · apache-iotdbEPSS 0.74%via OSV
CVE-2022-38369High· 8.8
4y ago

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

Twilightapache-iotdb · apache-iotdbEPSS 1.2%via OSV
apache-iotdb vulnerabilities (CVEs) · VulnSea