CVE-2026-62353

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL queries to crash the server and possibly leak adjacent memory. This issue is fixed in version 3.4.1.14.
Configurations

No configuration.

History

15 Jul 2026, 20:18

Type Values Removed Values Added
References () https://github.com/taosdata/TDengine/security/advisories/GHSA-5r9p-3j4f-gmgp - () https://github.com/taosdata/TDengine/security/advisories/GHSA-5r9p-3j4f-gmgp -

15 Jul 2026, 19:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 19:18

Updated : 2026-07-15 20:18


NVD link : CVE-2026-62353

Mitre link : CVE-2026-62353

CVE.ORG link : CVE-2026-62353


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read

CWE-126

Buffer Over-read