https://seclists.org/oss-sec/2026/q3/114: CVE-2026-40007: Apache IoTDB: Unauthenticated unbounded cursion in IoTDB AirGap ceiver's E-language pfix parser causes per-connection StackOverflowError
Published Jul 10, 2026
·Updated
Affected Software
1 affected component
Apache IoTDB>1.0.0<2.0.10
Frequently Asked Questions
1
What is the severity of CVE-2026-40007?
The severity of CVE-2026-40007 is moderate.
2
What versions of Apache IoTDB are affected by CVE-2026-40007?
Apache IoTDB versions prior to 2.0.10 are affected by CVE-2026-40007.
3
How does CVE-2026-40007 affect Apache IoTDB?
CVE-2026-40007 leads to unauthenticated unbounded recursion in the IoTDB AirGap receiver's E-language pfix parser.
4
How do I fix CVE-2026-40007?
To mitigate CVE-2026-40007, upgrade Apache IoTDB to version 2.0.10 or later.
5
What is the main cause of the vulnerability CVE-2026-40007?
CVE-2026-40007 is caused by uncontrolled recursion in the readLength method when pipe_air_gap_receiver_enabled is set to true.