What is CVE-2026-44630?
Improper validation of length fields in Apache IoTDB's RPC service may lead to a denial-of-service attack by remote unauthenticated attackers. A crafted malformed Thrift frame can cause excessive memory allocation, resulting in a crash with an OutOfMemoryError. Users should apply the relevant security updates.
Azərbaycanca: Apache IoTDB-nin RPC xidmətində uzunluq sahələrinin düzgün yoxlanılmaması uzaqdan autentifikasiya olunmamış hücumçuya xidmətin dayandırılmasına (denial of service) səbəb ola bilər. Xüsusi hazırlanmış Thrift çərçivəsi ilə həddindən artıq yaddaş ayrılmasına və OutOfMemoryError ilə çökməsinə yol aça bilər. IoTDB istifadəçiləri təhlükəsizlik yeniləmələrini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ1
What outcome can an attacker achieve by exploiting CVE-2026-44630 in Apache IoTDB?
A remote unauthenticated attacker can send a crafted malformed Thrift frame to cause excessive memory allocation, resulting in a crash with an OutOfMemoryError and leading to a denial-of-service condition.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.