Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose URL host matched the conf
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Temporal Technologies, Inc. | Temporal Server | 1.30.0< 1.30.7 |
affected |
1.31.0< 1.31.3 |
affected | ||
1.25.0≤ 1.29.7 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Temporal Technologies, Inc. | Temporal Server | 1.30.0 ~ 1.30.7 |
cpe:2.3:a:temporal:temporal:*:*:*:*:*:*:*:*
|
|
| Temporal Technologies, Inc. | Temporal Server | 1.25.0 ~ 1.29.7 |
cpe:2.3:a:temporal:temporal:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89139 | 8.7 HIGH | Temporal Server worker deployment compute provider executes a caller-supplied command on t |
| CVE-2026-65653 | 8.7 HIGH | temporalio/tchannel-go zero-chunk call fragment causes process termination |
| CVE-2026-65654 | 8.7 HIGH | temporalio/ringpop-go fails to enforce configured label limits on inbound membership gossi |
| CVE-2026-65652 | 8.7 HIGH | temporalio/tchannel-go malformed checksum type causes process termination |
| CVE-2026-16652 | 7.1 HIGH | Temporal Server Schedule exclusion search can cause excessive CPU consumption |
| CVE-2026-16651 | 7.1 HIGH | temporalio/sqlparser malformed MySQL version comments can cause a panic |
| CVE-2026-65651 | 6.0 MEDIUM | temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow duri |
No comments yet