apache-iotdb has 4 CVEs on record between 2022 and 2026. 3 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 8.9 (high), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.9
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- apache-iotdb 4
Worst active — by depth score
CVE-2026-24014Critical· 9.8Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path wit…54CVE-2026-24013Critical· 9.1Authentication Bypass by Spoofing vulnerability in Apache IoTDB.50CVE-2022-38369High· 8.8Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.49CVE-2026-24012High· 7.5Uncontrolled Resource Consumption vulnerability in Apache IoTDB. 41
apache-iotdb vulnerabilities
CVEs affecting apache-iotdb, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-24014Critical· 9.8Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path wit…
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an…
CVE-2026-24013Critical· 9.1Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing open…
CVE-2026-24012High· 7.5Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
Uncontrolled Resource Consumption vulnerability in Apache IoTDB. Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g.…
CVE-2022-38369High· 8.8Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.