TDengine is a time-series database platform with a focused product footprint, alongside associated monitoring and visualization integrations such as Grafana. Its observed vulnerability surface centers on input-handling and command-injection risks, reflecting the parsing demands of a database query and data-ingestion layer. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tdengine over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42542HIGH TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the tao | Jun 10, 2026 | 7.5 | 32 | NO | NO |
CVE-2023-34111CRITICAL The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary code execution within the gith | Jun 6, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-38502MEDIUM TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDengine DataBase crashes on UDF nested query. This issue affec | Jul 25, 2023 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tdengine.
Media articles that mention a CVE ID that affects a product developed by Tdengine — matched by CVE ID, not by vendor name.