TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 10 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue. | |
| Title | TDengine has an integer underflow in uvConnMayGetUserInfo() allows unauthenticated remote crash (DoS) | |
| Weaknesses | CWE-191 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-10T20:32:38.985Z
Reserved: 2026-04-28T16:56:50.190Z
Link: CVE-2026-42542
No data.
Status : Received
Published: 2026-06-10T22:16:57.527
Modified: 2026-06-10T22:16:57.527
Link: CVE-2026-42542
No data.
OpenCVE Enrichment
Updated: 2026-06-10T23:00:20Z
Weaknesses