Security Advisory

CVE-2026-40007

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-10 07:12:29
Last updated 2026-07-10 14:54:55
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap receiver's readLength method calls itself recursively each time it recognises the E-language prefix in socket data, with no depth limit. An unauthenticated attacker can send a stream of repeated E-language prefixes that drives the recursion arbitrarily deep, exhausting the receiver thread's JVM stack and raising StackOverflowError. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.