VYPR

Temporal

by Temporalio

Source repositories

CVEs (11)

  • CVE-2026-89139HigSep 21, 2026
    risk 0.50cvss —epss 0.01

    Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker Service. The program name and the…

  • CVE-2026-65651HigSep 21, 2026
    risk 0.50cvss —epss 0.01

    temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that…

  • CVE-2026-16651HigSep 21, 2026
    risk 0.50cvss —epss 0.00

    temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by strings.IndexFunc before using it as a…

  • CVE-2026-5724MedApr 10, 2026
    risk 0.41cvss —epss 0.01

    The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/StreamWorkflowReplicationMessages endp…

  • CVE-2026-87858HigSep 21, 2026
    risk 0.40cvss —epss 0.01

    Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose URL host matched the configured callback…

  • CVE-2026-16652HigSep 21, 2026
    risk 0.39cvss —epss 0.00

    Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create or update a Schedule that combines a fine-grained cadence with an exclusion calendar that rejects every…

  • CVE-2025-8396MedSep 15, 2025
    risk 0.38cvss —epss 0.00

    Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed…

  • CVE-2025-14987MedDec 30, 2025
    risk 0.27cvss —epss 0.00

    When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWorkflowExecution, RequestCancelExternalWorkflowExecution) to target a different namespace than the…

  • CVE-2024-2689MedApr 3, 2024
    risk 0.22cvss 4.4epss 0.00

    Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an invalid UTF-8 string for submission to potentially cause a crashloop. If left unchecked, the task…

  • CVE-2026-5199LowApr 1, 2026
    risk 0.08cvss —epss 0.00

    A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation requires the attacker to know or guess specific victim workflow ID(s) and, for signal operations, signal names.…

  • CVE-2025-14986LowDec 30, 2025
    risk 0.01cvss —epss 0.00

    When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows…