Resource exhaustion in Apache IoTDB - CVE-2026-24012
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in aggregation query interface when processing queries with extreme time span and aggregation interval parameters. A remote attacker can send a specially crafted query to cause a denial of service.
The issue can exhaust the Java heap and crash the DataNode process.