SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-40006

HIGH · CVSS 7.5 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Apache IoTDB versions 1.0.0 to prior to 2.0.10 are vulnerable due to an unauthenticated TCP connection acceptance on port 9780, allowing attackers to manipulate memory allocation through the readLength method. This can lead to heap memory exhaustion, potentially crashing or degrading the DataNode process significantly. Organizations using affected versions should prioritize upgrading to version 2.0.10 to mitigate this high-severity vulnerability.

CVE
CVE-2026-40006
Severity
HIGH
CVSS
7.5
EPSS
0.42%
Apache

Original NVD Description

Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap pipe receiver accepts raw TCP connections on port 9780 with no authentication. The readLength method reads an attacker-controlled 32-bit integer from the socket and readData passes it directly to new byte[length] with no upper-bound check. An unauthenticated attacker can cause the JVM to attempt an allocation of up to 2,147,483,647 bytes per connection, exhausting heap memory and crashing or severely degrading the DataNode process. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.