github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then unconditionally selected the first element. A network peer can
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Temporal Technologies, Inc. | temporalio/tchannel-go | 0.0.0-20150531204735-8d8ca17342b3< 1.22.1-0.20260720194454-0cb017f6870a |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Temporal Technologies, Inc. | temporalio/tchannel-go | 0.0.0-20150531204735-8d8ca17342b3 ~ 1.22.1-0.20260720194454-0cb017f6870a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89139 | 8.7 HIGH | Temporal Server worker deployment compute provider executes a caller-supplied command on t |
| CVE-2026-65654 | 8.7 HIGH | temporalio/ringpop-go fails to enforce configured label limits on inbound membership gossi |
| CVE-2026-65652 | 8.7 HIGH | temporalio/tchannel-go malformed checksum type causes process termination |
| CVE-2026-87858 | 7.2 HIGH | Temporal Server completion callback source header can direct attacker-chosen requests to t |
| CVE-2026-16652 | 7.1 HIGH | Temporal Server Schedule exclusion search can cause excessive CPU consumption |
| CVE-2026-16651 | 7.1 HIGH | temporalio/sqlparser malformed MySQL version comments can cause a panic |
| CVE-2026-65651 | 6.0 MEDIUM | temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow duri |
No comments yet