CVE-2026-42542(tdengine / tdengine)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-191

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tdengine

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
tdengine

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-24: 109-24
Referenced assets1 URL
Full discourse1 post
  • Ridge Security Technology Inc.@RidgeSecurityAI

    Worth a read if you run time-series databases in OT or IoT environments: https://ridgesecurity.ai/blog/one-packet-can-take-down-the-database-behind-industrial-operations-ridge-security-discovers-cve-2026-42542/ Ridge Security's research team disclosed CVE-2026-42542 (CVSS 7.5), a pre-authentication flaw in TDengine's RPC handler. A signed length value from the network is subtracted from an unsigned header size before any bounds check. That lets an undersized value wrap to a huge number that gets passed to memcpy(), so a single malformed packet to port 6030 crashes taosd. Versions 3.4.0.0 through 3.4.1.5 are affected, and the fix is in 3.4.1.6. #VulnerabilityResearch #OTSecurity #IoTSecurity #CVE

    0000050
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptdenginetdengine---

Explore more