{
  "from_raw": "Haonan Hou <haonan@apache.org>",
  "from": "Haonan Hou <ha...@apache.org>",
  "gravatar": "077d6b3571cf3c6b81dadb75bcf8f139",
  "to": "an...@apache.org,\n de...@iotdb.apache.org",
  "subject": "CVE-2026-44630: Apache IoTDB: RPC service denial of service via unchecked Thrift string length",
  "message-id": "<4aaa45d8-ca68-b739-563f-900ed9fd6c91@apache.org>",
  "mid": "tfsgd9whbq79lgjvdzj44hw0fhsofly8",
  "permalinks": [
    "tfsgd9whbq79lgjvdzj44hw0fhsofly8",
    "rd7c350e2629835fa682e0b2dc683df1cf632c6e7e63011e98b92a7c8@<announce.apache.org>"
  ],
  "dbid": "b71764bdc1e2d071e721566916f3bf5f2889f2ca362ba44132c63d8ce4764202",
  "cc": "de...@iotdb.apache.org",
  "epoch": 1786344442,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/08/10 06:47:22",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache IoTDB before 1.3.8\n- Apache IoTDB 2.0.0 before 2.0.10\n\nDescription:\n\nImproper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sending a crafted malformed Thrift frame, an attacker can cause IoTDB to allocate an excessive amount of memory and crash with an OutOfMemoryError.\n\n\nThis issue affects Apache IoTDB: before 1.3.8, from 2.0.0 before 2.0.9.\n\nUsers are recommended to upgrade to version 2.0.10, which fixes the issue.\n\nReferences:\n\nhttps://iotdb.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-44630\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache IoTDB before 1.3.8\n- Apache IoTDB 2.0.0 before 2.0.10\n\nDescription:\n\nImproper validation of length fields in the Apache IoTDB RPC service may allow a ",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3279,
  "id": "tfsgd9whbq79lgjvdzj44hw0fhsofly8"
}