๐Ÿ” CVE Alert

CVE-2026-42542

HIGH 7.5

TDengine has an integer underflow in uvConnMayGetUserInfo() allows unauthenticated remote crash (DoS)

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue.

CWE CWE-191
Vendor taosdata
Product tdengine
Published Jun 10, 2026
Stay Ahead of the Next One

Get instant alerts for taosdata tdengine

Be the first to know when new high vulnerabilities affecting taosdata tdengine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

taosdata / TDengine
>= 3.4.0.0, < 3.4.1.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/taosdata/TDengine/security/advisories/GHSA-vg95-j2hf-hvjx github.com: https://github.com/taosdata/TDengine/releases/tag/ver-3.4.1.6