Executive brief
Apache IoTDB, a database designed for managing large amounts of time-series data, is vulnerable to a denial-of-service attack. An attacker can send a specially crafted query that requests an extremely large amount of data at once, overwhelming the system's memory. This causes the database to crash, leading to service outages and preventing legitimate users or applications from accessing their data.
Technical details
A vulnerability in the query interface of Apache IoTDB allows for uncontrolled resource consumption (CWE-400). The software fails to validate or impose reasonable limits on the time span and aggregation interval parameters within incoming queries. By constructing a request with a very large time range and a minimal aggregation interval, an attacker can force the DataNode to attempt to build an enormous result set in memory. This exhausts the Java heap space, resulting in an OutOfMemoryError and a crash of the DataNode process. The issue is fixed in version 2.0.8.
Affected products
- Apache IoTDB 1.3.3 to 2.0.7
Timeline
- 2026-07-06: advisory
- 2026-07-06: disclosed
- 2026-07-06: patched: Fixed in version 2.0.8