TDengine是中国TDengine公司开源的一款开源、高性能、云原生时间序列数据库。 TDengine 3.4.1.14之前版本存在缓冲区错误漏洞,该漏洞源于SQL字符串字面量中尾部反斜杠的处理问题,导致解析过程中读取超出空终止符一个字节,可能允许经过身份验证的用户提交SQL查询时导致服务器崩溃并泄露相邻内存。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62349 | 8.3 HIGH | TDengine: Off-by-One Buffer Overflow |
| CVE-2026-62351 | 7.5 HIGH | TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in transDecompre |
| CVE-2026-62350 | 7.2 HIGH | TDengine: UDF lead to RCE |
| CVE-2026-62348 | 5.4 MEDIUM | TDengine: KILL SSMIGRATE missing authorization lets low-privilege users interrupt shared-s |
| CVE-2026-62355 | 5.4 MEDIUM | TDengine: Standard User permission unexpect |
No comments yet