github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard initialization handshake and send a call request with an unsupported checksu
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Temporal Technologies, Inc. | temporalio/tchannel-go | 0.0.0-20160105034737-a6904155f628< 1.22.1-0.20260720194454-0cb017f6870a |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Temporal Technologies, Inc. | temporalio/tchannel-go | 0.0.0-20160105034737-a6904155f628 ~ 1.22.1-0.20260720194454-0cb017f6870a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89139 | 8.7 HIGH | Temporal Server worker deployment compute provider executes a caller-supplied command on t |
| CVE-2026-65653 | 8.7 HIGH | temporalio/tchannel-go zero-chunk call fragment causes process termination |
| CVE-2026-65654 | 8.7 HIGH | temporalio/ringpop-go fails to enforce configured label limits on inbound membership gossi |
| CVE-2026-87858 | 7.2 HIGH | Temporal Server completion callback source header can direct attacker-chosen requests to t |
| CVE-2026-16652 | 7.1 HIGH | Temporal Server Schedule exclusion search can cause excessive CPU consumption |
| CVE-2026-16651 | 7.1 HIGH | temporalio/sqlparser malformed MySQL version comments can cause a panic |
| CVE-2026-65651 | 6.0 MEDIUM | temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow duri |
No comments yet