Vulnerability Description
Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sending a crafted malformed Thrift frame, an attacker can cause IoTDB to allocate an excessive amount of memory and crash with an OutOfMemoryError. This issue affects Apache IoTDB: before 1.3.8, from 2.0.0 before 2.0.9. Users are recommended to upgrade to version 2.0.10, which fixes the issue.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/tfsgd9whbq79lgjvdzj44hw0fhsofly8
- http://www.openwall.com/lists/oss-security/2026/08/10/1
FAQ
What is CVE-2026-44630?
CVE-2026-44630 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sending a crafted malformed Thrift frame, an attacker ...
How severe is CVE-2026-44630?
CVE-2026-44630 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44630?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.