Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
CVE-2026-40008
Description
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pipe processor reads a fully qualified Java class name and instantiates it using Class.forName().newInstance() without any validation or allowlisting.
This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.
Users are recommended to upgrade to version 2.0.10, which fixes the issue.
Affected products
1Patches
Vulnerability mechanics
References
1- lists.apache.org/thread/fm8cpvzbox2qqy99ztglm8wkk1nrg9ngmitrevendor-advisory
News mentions
0No linked articles in our index yet.