Where
-Infinity
0

Apache IoTDBApache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users

Risk 46
Severity
7.5
First published (updated )

Apache IoTDBApache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor

Risk 40
Severity
6.5
First published (updated )

Apache IoTDBApache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC

Risk 90
Severity
9.8
First published (updated )

Apache IoTDBApache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError

Risk 46
Severity
7.5
First published (updated )

Apache IoTDBApache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache IoTDBApache IoTDB: Path Traversal in Pipe File Transfer Receiver

Risk 70
Severity
9.1
First published (updated )

Apache IoTDBApache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials

Risk 90
Severity
9.8
First published (updated )

oss-secCVE-2026-40452: Apache IoTDB: Authorization bypass in /st/v2/fastLastQuery exposes last-value data to unauthorized authenticated users

oss-secCVE-2026-40009: Apache IoTDB: Authenticated users can escalate to full te-path access by naming themselves to __internal_auditor

oss-secCVE-2026-40008: Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-secCVE-2026-40007: Apache IoTDB: Unauthenticated unbounded cursion in IoTDB AirGap ceiver's E-language pfix parser causes per-connection StackOverflowError

oss-secCVE-2026-40006: Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe ceiver

oss-secCVE-2026-40005: Apache IoTDB: Path Traversal in Pipe File Transfer ceiver

oss-secCVE-2026-28564: Apache IoTDB: ST Basic Authentication Accepts Stale Cached Cdentials

Apache IoTDBApache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC

Risk 70
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache IoTDBApache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query

Risk 46
Severity
7.5
First published (updated )

Apache IoTDBApache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write

Risk 90
Severity
9.8
First published (updated )

oss-secCVE-2026-24014: Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write

First published (updated )

oss-secCVE-2026-24013: Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC

First published (updated )

oss-secCVE-2026-24012: Apache IoTDB: Denial of Service via source Exhaustion in Agggation Query

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache IoTDBApache IoTDB: Insecure Default Configuration Vulnerability

Risk 91
Severity
9.8
First published (updated )

oss-secCVE-2026-24015: Apache IoTDB: InsecuDefault Configuration Vulnerability

Apache IoTDBApache IoTDB: JEXL Expression Injection Vulnerability

Risk 91
Severity
9.8
First published (updated )

oss-secCVE-2026-24713: Apache IoTDB: JEXL Expssion Injection Vulnerability

Apache IoTDBApache IoTDB: Path Traversal Vulnerability

Risk 70
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache IoTDBApache IoTDB: Path Traversal Vulnerability

Risk 70
Severity
9.1
First published (updated )

oss-secCVE-2025-55017: Apache IoTDB: Path Traversal Vulnerability

Apache IoTDBApache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication

Risk 46
Severity
7.5
First published (updated )

Apache IoTDBApache IoTDB: Remote Code Execution with untrusted URI of User-defined function

Risk 91
Severity
9.8
First published (updated )

CVE-2025-26864: Apache IoTDB: Exposuof Sensitive Information in IoTDB OpenID Authentication

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203