Vulnerability
Published 2026-09-23
Verified 2026-09-27

TDengine CVE-2026-42542 (CVSS 7.5): unauth RPC integer underflow → taosd crash (port 6030); fix 3.4.1.6 — Ridge / vendor

Ridge Security (public write-up 23 September 2026; SecurityWeek In Other News 25 Sep) and TDengine security advisories document CVE-2026-42542 (TD-SEC-2026-001; GHSA-vg95-j2hf-hvjx; vendor published 4 June 2026; reporter Yan @ Ridge Security): an integer underflow in uvConnMayGetUserInfo() (transSvr.c) on the pre-authentication RPC path lets an unauthenticated remote attacker crash taosd with one crafted packet to the default TCP 6030 listener (CWE-191). Confirmed impact is denial of service (heap overflow / SIGSEGV); Ridge does not claim RCE and reports no in-the-wild exploitation telemetry. CVSS 7.5 HIGH. Affected: TDengine >= 3.4.0.0 through 3.4.1.5; fixed in 3.4.1.6. Relevant to industrial telemetry, energy/utilities, IoT and OT monitoring stacks that embed TDengine. Primary: Ridge Security blog + TDengine security advisories / GHSA.

Product
TDengine (taosd) time-series database — RPC on TCP 6030
Versions
Affected: >= 3.4.0.0, <= 3.4.1.5. Fixed: 3.4.1.6 and later.
CVSS
7.5
Exploited in Australia?
unknown
Patch to
Upgrade TDengine to 3.4.1.6 or later; restrict TCP 6030 to authorised application hosts only (not internet-facing); inventory OEM/bundled TDengine in OT/IoT stacks; monitor taosd crash/restart loops correlated with untrusted RPC sources.

Primary: Ridge Security — TDengine CVE-2026-42542 one-packet DoS (23 Sep 2026) · Vendor: TDengine — Security Advisories (CVE-2026-42542 / TD-SEC-2026-001) · CVE: CVE-2026-42542 · GitHub GHSA-vg95-j2hf-hvjx — TDengine RPC integer underflow DoS

vulnerabilities ot ics network