CVE-2026-62353

MEDIUM

TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken

Title source: cna
STIX 2.1

Description

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL queries to crash the server and possibly leak adjacent memory. This issue is fixed in version 3.4.1.14.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0025
EPSS Percentile 16.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-125 CWE-126
Status published
Products (1)
taosdata/TDengine < 3.4.1.14
Published Jul 15, 2026
Tracked Since Jul 16, 2026