CVE-2026-42542
EUVD-2026-3613610.06.2026, 22:16
TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tdengine | tdengine | 3.4.0.0 ≤ 𝑥 < 3.4.1.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration