Sploitus

CVE-2026-62353

No indexed exploits for CVE-2026-62353 yet

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL queries to crash the server and possibly leak adjacent memory. This issue is fixed in version 3.4.1.14.

Affected products
Tdengine
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.2% (16th percentile)
Weakness
CWE-126, CWE-125
NVD status
Deferred
Published
2026-07-15
CVE-2026-62353 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-62353 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-62353 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.