{"id":"PYSEC-2026-2079","details":"Uncontrolled Resource Consumption vulnerability in Apache IoTDB. \n\nSome interface fails to impose reasonable\nlimits on the time span and aggregation interval of the query. An attacker\ncan construct a request with extreme parameters (e.g., a very large time\nrange combined with a minimal interval). This forces the DataNode to build\nan enormous result set in memory, which exhausts the Java heap and causes\nthe DataNode process to crash.\n\nThis issue affects Apache IoTDB: from 1.3.3 before 2.0.8.\n\nUsers are recommended to upgrade to version 2.0.8, which fixes the issue.","aliases":["CVE-2026-24012"],"modified":"2026-07-08T11:30:04.841210553Z","published":"2026-07-06T09:16:35.037Z","references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2026/07/06/10"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/0g5th1t2vj6j8hm5t9w3xh9n6f6ht9z8"}],"affected":[{"package":{"name":"apache-iotdb","ecosystem":"PyPI","purl":"pkg:pypi/apache-iotdb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.3.3"},{"fixed":"2.0.8"}]}],"versions":["1.3.3","1.3.4","2.0.1b0","2.0.2","2.0.3","2.0.4","2.0.4.dev0","2.0.5","2.0.6"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/apache-iotdb/PYSEC-2026-2079.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}