VYPR
Vendor

Temporalio

Products
8
CVEs
18
Across products
20
Status
Private

Products

8

Recent CVEs

18
  • CVE-2026-96770CriSep 23, 2026
    risk 0.53cvss —epss 0.00

    All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when skipCAVerification is false. This mode checks that the client holds the certificate's private key but does not verify the…

  • CVE-2026-89139HigSep 21, 2026
    risk 0.50cvss —epss 0.01

    Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker Service. The program name and the…

  • CVE-2026-65654HigSep 21, 2026
    risk 0.50cvss —epss 0.01

    github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes. A network peer that can reach a live Ringpop TChannel…

  • CVE-2026-65653HigSep 21, 2026
    risk 0.50cvss —epss 0.01

    github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then unconditionally selected the first element. A network peer can supply such a…

  • CVE-2026-65652HigSep 21, 2026
    risk 0.50cvss —epss 0.01

    github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard initialization handshake and send a call request with an unsupported checksum type. The parser…

  • CVE-2026-65651HigSep 21, 2026
    risk 0.50cvss —epss 0.01

    temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that…

  • CVE-2026-16651HigSep 21, 2026
    risk 0.50cvss —epss 0.00

    temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by strings.IndexFunc before using it as a…

  • CVE-2026-5724MedApr 10, 2026
    risk 0.41cvss —epss 0.01

    The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/StreamWorkflowReplicationMessages endp…

  • CVE-2026-87858HigSep 21, 2026
    risk 0.40cvss —epss 0.01

    Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose URL host matched the configured callback…

  • CVE-2026-16652HigSep 21, 2026
    risk 0.39cvss —epss 0.00

    Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create or update a Schedule that combines a fine-grained cadence with an exclusion calendar that rejects every…

  • CVE-2025-8396MedSep 15, 2025
    risk 0.38cvss —epss 0.00

    Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed…

  • CVE-2025-14987MedDec 30, 2025
    risk 0.27cvss —epss 0.00

    When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWorkflowExecution, RequestCancelExternalWorkflowExecution) to target a different namespace than the…

  • CVE-2024-2689MedApr 3, 2024
    risk 0.22cvss 4.4epss 0.00

    Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an invalid UTF-8 string for submission to potentially cause a crashloop. If left unchecked, the task…

  • CVE-2024-2435MedApr 2, 2024
    risk 0.21cvss 4.3epss 0.00

    For an attacker with pre-existing access to send a signal to a workflow, the attacker can make the signal name a script that executes when a victim views that signal. The XSS is in the timeline page displaying the workflow execution details of the workflow that was sent the…

  • CVE-2026-65655LowAug 11, 2026
    risk 0.08cvss —epss 0.00

    When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-server connection. Temporal UI Server can…

  • CVE-2026-5199LowApr 1, 2026
    risk 0.08cvss —epss 0.00

    A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation requires the attacker to know or guess specific victim workflow ID(s) and, for signal operations, signal names.…

  • CVE-2025-1243LowFeb 12, 2025
    risk 0.06cvss —epss 0.00

    The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module was used in a gRPC proxy prior to transmission. This resulted in information contained within the `update response`…

  • CVE-2025-14986LowDec 30, 2025
    risk 0.01cvss —epss 0.00

    When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows…