https://seclists.org/oss-sec/2026/q1/285: CVE-2026-24713: Apache IoTDB: JEXL Expssion Injection Vulnerability
Published Mar 9, 2026
·Updated
Affected Software
1 affected component
Apache IoTDB<1.3.7, <2.0.7
Frequently Asked Questions
1
What is the severity of CVE-2026-24713?
The severity of CVE-2026-24713 is classified as important.
2
Which versions of Apache IoTDB are affected by CVE-2026-24713?
CVE-2026-24713 affects Apache IoTDB versions 1.0.0 before 1.3.7 and 2.0.0 before 2.0.7.
3
How do I fix CVE-2026-24713?
To fix CVE-2026-24713, users should upgrade to Apache IoTDB version 1.3.7 or later, or version 2.0.7 or later.
4
What is the nature of the vulnerability in CVE-2026-24713?
CVE-2026-24713 is an improper input validation vulnerability within Apache IoTDB.
5
When was CVE-2026-24713 published?
CVE-2026-24713 was published on March 9, 2026.