All 8 CVE vulnerabilities found in TDengine, with AI-generated Chinese analysis, references, and POCs.
Vendor: taosdata
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-62353 | TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken CWE-125 | 5.4 | Medium | 2026-07-15 |
| CVE-2026-62351 | TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in transDecompressMsg CWE-125 | 7.5 | High | 2026-07-15 |
| CVE-2026-62348 | TDengine: KILL SSMIGRATE missing authorization lets low-privilege users interrupt shared-storage migrations CWE-862 | 5.4 | Medium | 2026-07-15 |
| CVE-2026-62349 | TDengine: Off-by-One Buffer Overflow CWE-121 | 8.3 | High | 2026-07-15 |
| CVE-2026-62350 | TDengine: UDF lead to RCE CWE-94 | 7.2 | High | 2026-07-15 |
| CVE-2026-62355 | TDengine: Standard User permission unexpect CWE-269 | 5.4 | Medium | 2026-07-15 |
| CVE-2026-42542 | TDengine has an integer underflow in uvConnMayGetUserInfo() allows unauthenticated remote crash (DoS) CWE-191 | 7.5 | High | 2026-06-10 |
| CVE-2023-38502 | TDengine Database Denial-of-Service CWE-20 | 6.5 | Medium | 2023-07-25 |
All 8 known CVE vulnerabilities affecting TDengine with full Chinese analysis, references, and POCs where available.