Apache · Apache Iotdb · CVE-2026-24012
**Name of the Vulnerable Software and Affected Versions**
Apache IoTDB versions 1.3.3 through 2.0.7
**Description**
An uncontrolled resource consumption issue exists where certain interfaces do not impose reasonable limits on the time span and aggregation interval of queries. An attacker can send a request using extreme parameters, such as a very large time range combined with a minimal interval, forcing the DataNode to build an enormous result set in memory. This leads to Java heap exhaustion and causes the DataNode process to crash.
**Recommendations**
Upgrade to version 2.0.8.