TDengine CVE-2026-42542: one packet crashes taosd unauthenticated
Ridge Security disclosed CVE-2026-42542 in TDengine: a single unauthenticated packet to TCP/6030 triggers an integer underflow and crashes the taosd process. Versions 3.4.0.0 through 3.4.1.5 are affected; the fix ships in 3.4.1.6. Only denial of service is confirmed, with no evidence of RCE or active exploitation.
- A single packet to TCP/6030 crashes taosd via integer underflow
- TDengine 3.4.0.0–3.4.1.5 affected, fixed in 3.4.1.6
- Repeated packets sustain a restart loop and telemetry gaps
- Only DoS confirmed; RCE and real-world attacks unproven
Read next
Security