Description
Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
1.0.0 (semver) before 2.0.5
Credits
Sanny
75Acol
stan fang
Wu Jiang
References
www.openwall.com/lists/oss-security/2025/09/24/8
lists.apache.org/thread/mr84n19nv8d0bmcrfsj3mm5ff5qn4q2f