VYPR

IoTDB DataNode

by Apache

CVEs (1)

  • CVE-2026-24014CriJul 6, 2026
    risk 0.00cvss 9.8epss 0.01

    Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal…