cbcvebase.

Apache Software Foundation Apache Iotdb vulnerabilities

24 known vulnerabilities affecting apache_software_foundation/apache_iotdb.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH9MEDIUM2

Vulnerabilities

Page 2 of 2
CVE-2022-43766P3HIGHCVSS 7.5≥ unspecified, ≤ 0.13.2≥ 0.12.2, < unspecified2022-10-26
CVE-2022-43766 [HIGH] CWE-400 CVE-2022-43766: Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.
nvd
CVE-2022-38369P3HIGHCVSS 8.8v0.13.02022-09-05
CVE-2022-38369 [HIGH] CWE-384 CVE-2022-38369: Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13 Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
nvd
CVE-2026-40009P3MEDIUMCVSS 6.5≥ 2.0.8, < 2.0.102026-07-10
CVE-2026-40009 [MEDIUM] CWE-269 CVE-2026-40009: Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor. This issue affects Apache IoTDB: from 2.0.8 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.
nvd
CVE-2025-48459P3MEDIUMCVSS 5.3≥ 1.0.0, < 2.0.52025-09-24
CVE-2025-48459 [MEDIUM] CWE-502 CVE-2025-48459: Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: f Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue.
nvd
Apache Software Foundation Apache Iotdb vulnerabilities | cvebase