CVE-2025-48392: Apache Iotdb

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to upgrade to version 2.0.5, which fixes the issue.

Affected products

  • Apache Iotdb: from 1.3.3, up to and including 1.3.4; from 2.0.1, before 2.0.5 (fixed in 2.0.5)

Published 2025-09-24. Last modified 2026-09-26.