Executive brief
The Apache IoTDB C++ client, used for connecting applications to the IoTDB database, contains a vulnerability that can cause the client application to crash. If the client receives specially crafted, malicious data from a server, it may fail to process it correctly and terminate unexpectedly. This can lead to service disruptions and loss of connectivity for applications relying on the database.
Technical details
An out-of-bounds read and improper input validation vulnerability exists in the Apache IoTDB C++ client's TsBlock deserializer. The flaw is triggered when the client attempts to deserialize malformed data received from a server. An attacker capable of sending or spoofing server responses can cause the client process to crash, resulting in a denial-of-service (DoS) condition. The issue affects versions 1.3.5 through 1.3.7 and 2.0.5 through 2.0.9, and is resolved in version 2.0.10.
Affected products
- Apache Software Foundation IoTDB C++ client 1.3.5 to 1.3.7, 2.0.5 to 2.0.9
Timeline
- 2026-07-10: advisory: CVE-2026-40454 published by Apache Software Foundation
- 2026-07-10: patched: Version 2.0.10 released to address the vulnerability