Status: UPDATED | Advisory ID: CVE-2026-42542
| CVE | CVE-2026-42542 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-07-23 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | tdengine tdengine |
| Classified as | CWE-191 (Integer Underflow (Wrap or Wraparound)) |
| Exploitation prediction (EPSS) | 0.56% probability of exploitation in the next 30 days (44% percentile) -- FIRST.org's EPSS model. |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| tdengine | tdengine |
| Subsystems | General OT |
| Sectors | Multiple |
TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue. (NVD)
Monitor tdengine's web page for any future patch releases. See vendor advisory link below.