https://seclists.org/oss-sec/2026/q3/67: CVE-2026-24012: Apache IoTDB: Denial of Service via source Exhaustion in Agggation Query
Published Jul 6, 2026
·Updated
Affected Software
1 affected component
Apache IoTDB>=1.3.3<2.0.8
Frequently Asked Questions
1
What is the severity of CVE-2026-24012?
The severity of CVE-2026-24012 is considered moderate.
2
What versions of Apache IoTDB are affected by CVE-2026-24012?
Apache IoTDB versions 1.3.3 before 2.0.8 are affected by CVE-2026-24012.
3
How does CVE-2026-24012 affect Apache IoTDB?
CVE-2026-24012 allows for uncontrolled resource consumption leading to Denial of Service through aggregation queries.
4
How do I fix CVE-2026-24012?
To fix CVE-2026-24012, upgrade Apache IoTDB to version 2.0.8 or later.
5
What type of attack does CVE-2026-24012 facilitate?
CVE-2026-24012 facilitates Denial of Service attacks via source exhaustion in aggregation queries.