CVE-2026-24012
Last modified
CVE-2026-24012 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Uncontrolled Resource Consumption vulnerability in Apache IoTDB. Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g., a very large time range combined with a minimal interval). This forces the DataNode to build an enormous result set in memory, which exhausts the Java heap and causes the DataNode process to crash. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Uncontrolled Resource Consumption vulnerability in Apache IoTDB. Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g., a very large time range combined with a minimal interval). This forces the DataNode to build an enormous result set in memory, which exhausts the Java heap and causes the DataNode process to crash. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Iotdb | >= 1.3.3, < 2.0.8 |
References
- https://lists.apache.org/thread/0g5th1t2vj6j8hm5t9w3xh9n6f6ht9z8Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/06/10Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-24012?
How severe is CVE-2026-24012?
How do I fix CVE-2026-24012?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-24005Kruise provides automated management of large-scale applicat…7.6
- CVE-2026-24006Seroval facilitates JS value stringification, including comp…7.5
- CVE-2026-24007Tuleap is an Open Source Suite for management of software de…4.6
- CVE-2026-24009Docling Core (or docling-core) is a library that defines cor…9.8
- CVE-2026-2401CWE-532 Insertion of Sensitive Information into Log File vul…5
- CVE-2026-24010Horilla is a free and open source Human Resource Management …8
- CVE-2026-24013Authentication Bypass by Spoofing vulnerability in Apache Io…9.1
- CVE-2026-24014Apache IoTDB DataNode’s internal RPC interface for creating …9.8
- CVE-2026-24015A vulnerability in Apache IoTDB. This issue affects Apache …9.8
- CVE-2026-24016The installer of ServerView Agents for Windows provided by F…8.4
- CVE-2026-24017An Improper Control of Interaction Frequency vulnerability […8.1
- CVE-2026-24018A UNIX symbolic link (Symlink) following vulnerability in Fo…7.8
Are you affected by CVE-2026-24012?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
