SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-40454

HIGH · CVSS 7.5 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The Apache IoTDB C++ client is vulnerable to an out-of-bounds read due to improper input validation, which can lead to client crashes when processing malformed server data. This high-severity vulnerability impacts versions 1.3.5 to 1.3.8 and 2.0.5 to 2.0.10, and users should prioritize upgrading to version 2.0.10 to mitigate the risk. Organizations using affected versions should take immediate action to ensure system stability and security.

CVE
CVE-2026-40454
Severity
HIGH
CVSS
7.5
EPSS
0.33%
Apache

Original NVD Description

Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client process on malformed server data. This issue affects Apache IoTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.