High severity7.5NVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
CVE-2026-62351
CVE-2026-62351
Description
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contLen when pHead->comp == 1 without first validating that the RPC packet contained the 8-byte STransCompMsg structure, causing an unauthenticated out-of-bounds read, uncontrolled allocation, integer underflow, and server crash. This issue is fixed in version 3.4.1.15.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.