Junglewise Threat Intelligence

CVE-2025-26864: PYSEC-2025-60 - Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuth

CVE-2025-26864 · Severity: medium · CVSS 4 · Published 2025-05-14

Technologies: apache-iotdb (PyPI). Vendors: PyPI.

Executive brief

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB.

This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.

Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.

Affected products

  • PyPI apache-iotdb

Related threats