Input validation error in Apache IoTDB - CVE-2026-44630
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the RPC service when parsing crafted Thrift frames. A remote attacker can send a malformed Thrift frame to cause a denial of service.
The issue can trigger excessive memory allocation and terminate the process with an OutOfMemoryError.