CVE-2026-40454

CVE-2026-40454: Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data

Vendor Apache Software Foundation
Product Apache IoTDB C++ client
Weakness CWE-125
Published July 10, 2026
Last update July 10, 2026

CVSS base score

What the vulnerability does

01Description

Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client process on malformed server data. This issue affects Apache IoTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.

Key dates

02Disclosure timeline

July 10, 2026 CVE published
July 10, 2026 Record updated