← All Advisories

CVE-2026-42542

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-42542

Key Details

CVECVE-2026-42542
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-07-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productstdengine tdengine
Classified asCWE-191 (Integer Underflow (Wrap or Wraparound))
Exploitation prediction (EPSS)0.56% probability of exploitation in the next 30 days (44% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
tdenginetdengine
SubsystemsGeneral OT
SectorsMultiple

What to Know

TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue. (NVD)

What to Do

Monitor tdengine's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-42542
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-42542
Vendor advisoryhttps://github.com/taosdata/TDengine/security/advisories/GHSA-vg95-j2hf-hvjx