CVE-2026-24012: Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query

Published Jul 6, 2026
·
Updated

Uncontrolled Resource Consumption vulnerability in Apache IoTDB.

Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g., a very large time range combined with a minimal interval). This forces the DataNode to build an enormous result set in memory, which exhausts the Java heap and causes the DataNode process to crash.

This issue affects Apache IoTDB: from 1.3.3 before 2.0.8.

Users are recommended to upgrade to version 2.0.8, which fixes the issue.

Affected Software

2 affected components
Apache IoTDB>=1.3.3<2.0.8
Apache IoTDB>=1.3.3<2.0.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache IoTDB to a version that resolves this vulnerability.

    Fixed in 2.0.8
  2. Compensating control

    Mitigate ongoing DoS risk by restricting access to the DataNode/IoTDB query interface so attackers cannot send crafted aggregation queries with extreme parameters (e.g., very large time range combined with minimal aggregation interval).

Event History

Jul 6, 2026
CVE Published
via MITRE·08:38 AM
Data Sourced
via MITRE·08:38 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-24012?

CVE-2026-24012 has a high severity rating of 7.5 according to the CVSS v3.1.

2

How does CVE-2026-24012 exploit uncontrolled resource consumption?

CVE-2026-24012 allows an attacker to exhaust system resources by sending queries with extreme time spans and minimal aggregation intervals.

3

What are the potential impacts of CVE-2026-24012?

The primary impact of CVE-2026-24012 is denial of service, which can make the system unresponsive.

4

How can I mitigate CVE-2026-24012?

To mitigate CVE-2026-24012, impose limits on the time range and aggregation intervals of queries made to Apache IoTDB.

5

Is Apache IoTDB affected by CVE-2026-24012?

Yes, CVE-2026-24012 directly affects Apache IoTDB due to its lack of limits on query parameters.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203