CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-62353

mediumCVSS 5.4covered by 1 sourcefirst seen 2026-07-15
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL queries to crash the server and possibly leak adjacent memory. This issue is fixed in version 3.4.1.14.

⚡ Watch CVE-2026-62353

Get an email if CVE-2026-62353 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-62353

CVE.org record

Embed the live status

CVE-2026-62353 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-62353 status](https://www.csirts.com/badge/CVE-2026-62353)](https://www.csirts.com/cve/CVE-2026-62353)