CVE-2026-44630

CVE-2026-44630: Apache IoTDB: RPC service denial of service via unchecked Thrift string length

Vendor Apache Software Foundation
Product Apache IoTDB
Weakness CWE-789
Published August 10, 2026
Last update August 12, 2026

CVSS base score

What the vulnerability does

01Description

Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sending a crafted malformed Thrift frame, an attacker can cause IoTDB to allocate an excessive amount of memory and crash with an OutOfMemoryError. This issue affects Apache IoTDB: before 1.3.8, from 2.0.0 before 2.0.9. Users are recommended to upgrade to version 2.0.10, which fixes the issue.

Key dates

02Disclosure timeline

August 10, 2026 CVE published
August 12, 2026 Record updated