Sploitus

CVE-2026-62349

No indexed exploits for CVE-2026-62349 yet

TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \%, \_, or \x, allowing a one-byte out-of-bounds write to the stack buffer tmpTokenBuf that can cause denial of service and potentially remote code execution. This issue is fixed in version 3.4.1.14.

Affected products
Tdengine
Fix
Available
CVSS 3.1
8.3 HIGH
EPSS
0.4% (33th percentile)
Weakness
CWE-787, CWE-121
NVD status
Deferred
Published
2026-07-15
CVE-2026-62349 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-62349 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-62349 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.