Critical severityNVD Advisory· Published Mar 9, 2026· Updated Mar 10, 2026
Apache IoTDB: JEXL Expression Injection Vulnerability
CVE-2026-24713
Description
Improper Input Validation vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7.
Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.iotdb:iotdb-coreMaven | >= 1.0.0, < 1.3.7 | 1.3.7 |
org.apache.iotdb:iotdb-coreMaven | >= 2.0.0, < 2.0.7 | 2.0.7 |
Affected products
2- Apache Software Foundation/Apache IoTDBv5Range: 1.0.0
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-6w48-2g9j-v9q5ghsaADVISORY
- lists.apache.org/thread/vopgv6y2ccw403b0zv7rvojjrh7x1j5pghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-24713ghsaADVISORY
- www.openwall.com/lists/oss-security/2026/03/09/4ghsaWEB
- github.com/apache/iotdb/commit/8fbfddc5f83771f1b339c457de597fe877f686d2ghsaWEB
- github.com/apache/iotdb/compare/v1.3.6...v1.3.7ghsaWEB
- github.com/apache/iotdb/compare/v2.0.6...v2.0.7ghsaWEB
- github.com/apache/iotdb/releases/tag/v1.3.7ghsaWEB
- github.com/apache/iotdb/releases/tag/v2.0.7ghsaWEB
News mentions
0No linked articles in our index yet.