Junglewise Threat Intelligence

CVE-2026-24012: Apache IoTDB uncontrolled resource consumption in query interface

CVE-2026-24012 · Severity: low · CVSS 3.1 · Published 2026-07-06

Technologies: Apache IoTDB, Apache Software Foundation IoTDB. Vendors: Apache, PyPI, Apache Software Foundation.

Executive brief

Apache IoTDB, a database designed for managing large amounts of time-series data, is vulnerable to a denial-of-service attack. An attacker can send a specially crafted query that requests an extremely large amount of data at once, overwhelming the system's memory. This causes the database to crash, leading to service outages and preventing legitimate users or applications from accessing their data.

Technical details

A vulnerability in the query interface of Apache IoTDB allows for uncontrolled resource consumption (CWE-400). The software fails to validate or impose reasonable limits on the time span and aggregation interval parameters within incoming queries. By constructing a request with a very large time range and a minimal aggregation interval, an attacker can force the DataNode to attempt to build an enormous result set in memory. This exhausts the Java heap space, resulting in an OutOfMemoryError and a crash of the DataNode process. The issue is fixed in version 2.0.8.

Affected products

  • Apache IoTDB 1.3.3 to 2.0.7

Timeline

  • 2026-07-06: advisory
  • 2026-07-06: disclosed
  • 2026-07-06: patched: Fixed in version 2.0.8

References

Related threats