Junglewise Threat Intelligence

CVE-2026-40454: Apache IoTDB C++ client out-of-bounds read in TsBlock deserializer

CVE-2026-40454 · Severity: info · Published 2026-07-10

Vendors: Apache Software Foundation.

Executive brief

The Apache IoTDB C++ client, used for connecting applications to the IoTDB database, contains a vulnerability that can cause the client application to crash. If the client receives specially crafted, malicious data from a server, it may fail to process it correctly and terminate unexpectedly. This can lead to service disruptions and loss of connectivity for applications relying on the database.

Technical details

An out-of-bounds read and improper input validation vulnerability exists in the Apache IoTDB C++ client's TsBlock deserializer. The flaw is triggered when the client attempts to deserialize malformed data received from a server. An attacker capable of sending or spoofing server responses can cause the client process to crash, resulting in a denial-of-service (DoS) condition. The issue affects versions 1.3.5 through 1.3.7 and 2.0.5 through 2.0.9, and is resolved in version 2.0.10.

Affected products

  • Apache Software Foundation IoTDB C++ client 1.3.5 to 1.3.7, 2.0.5 to 2.0.9

Timeline

  • 2026-07-10: advisory: CVE-2026-40454 published by Apache Software Foundation
  • 2026-07-10: patched: Version 2.0.10 released to address the vulnerability

References