{
  "from_raw": "Haonan Hou <haonan@apache.org>",
  "from": "Haonan Hou <ha...@apache.org>",
  "gravatar": "077d6b3571cf3c6b81dadb75bcf8f139",
  "to": "an...@apache.org,\n de...@iotdb.apache.org",
  "subject": "CVE-2026-40008: Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC",
  "message-id": "<470827c7-35e3-de8f-7eb7-4794131b2e78@apache.org>",
  "mid": "fm8cpvzbox2qqy99ztglm8wkk1nrg9ng",
  "permalinks": [
    "fm8cpvzbox2qqy99ztglm8wkk1nrg9ng",
    "r155b173c5f6d24e82b0db41174ecd54a3a6ee2f37828d1650ba13c8a@<announce.apache.org>"
  ],
  "dbid": "ffde10eab5dc14255a9817a25148294e9c165a741fe71ded1fd4129f258da662",
  "cc": "de...@iotdb.apache.org",
  "epoch": 1783665114,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/07/10 06:31:54",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache IoTDB 1.0.0 before 2.0.10\n\nDescription:\n\nUse of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB.\nThe pipe processor reads a fully\nqualified Java class name and\ninstantiates it using Class.forName().newInstance() without any\nvalidation or allowlisting.\n\n\nThis issue affects Apache IoTDB: from 1.0.0 before 2.0.10.\n\nUsers are recommended to upgrade to version 2.0.10, which fixes the issue.\n\nCredit:\n\nAndrea Cosentino (finder)\n\nReferences:\n\nhttps://iotdb.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-40008\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache IoTDB 1.0.0 before 2.0.10\n\nDescription:\n\nUse of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Io",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2564,
  "id": "fm8cpvzbox2qqy99ztglm8wkk1nrg9ng"
}