{"ok":true,"trend":{"id":356461,"platform":"mastodon","region":"global","key":"🤖 cve-2026-42542 (cvss 7.5): integer underflow in tdengine's pre-auth rpc message parsing. a single crafted packet to tc","title":"🤖 CVE-2026-42542 (CVSS 7.5): integer underflow in TDengine's pre-auth RPC message parsing. A single crafted packet to TC","url":"https://infosec.exchange/@cloud/117354229639555670","first_seen":"2026-09-29T12:15:56.722891Z","last_seen":"2026-09-29T12:15:56.722891Z","last_rank":7,"peak_rank":7,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.93359375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A new vulnerability, CVE-2026-42542 with a CVSS score of 7.5, has been disclosed in TDengine, an open-source time-series database used in OT and IoT deployments. The flaw is an integer underflow in pre-authentication RPC message parsing: a single crafted packet sent to TCP port 6030 can crash unauthenticated servers. Versions 3.4.0.0 through 3.4.1.5 are affected, with a fix released in version 3.4.1.6. No exploitation in the wild has been reported so far, and a proof-of-concept has been withheld.","why":"Security professionals are sharing the disclosure so operators of exposed TDengine instances can patch before exploits emerge.","tone":"neutral","entities":["TDengine","CVE-2026-42542"],"summarized_at":"2026-09-29T12:17:40.241520Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1021},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"TDengine vulnerability lets unauthenticated packets crash servers","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-29T12:15:56.722891Z","rank":7,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@cloud/117354229639555670","author":"cloud@infosec.exchange","title":null,"snippet":"🤖 CVE-2026-42542 (CVSS 7.5): integer underflow in TDengine's pre-auth RPC message parsing. A single crafted packet to TCP/6030 crashes unauthenticated servers. Affects 3.4.0.0–3.4.1.5, fixed in 3.4.1.6. No in-the-wild exploitation yet; PoC withheld. Deployed in OT/IoT…","posted_at":"2026-09-29T12:03:55Z","likes":1}],"elsewhere":[],"window":"7d"}}