Parsing Vulnerability in Temporal Server by Temporal.io
CVE-2026-16651
What is CVE-2026-16651?
A vulnerability exists within the SQL parser of Temporal Server that could lead to a panic in the Go runtime when processing malformed MySQL version comments. If these comments are empty or consist solely of one to five decimal digits, the parser may fail to handle the response appropriately. This flaw allows an authenticated user with read permission to cause a denial-of-service condition by submitting a crafted query, which can crash the matching process of the server. The issue, while impacting availability, does not affect data confidentiality or integrity, making it crucial for developers to implement recovery strategies to prevent service interruptions.
Affected Version(s)
Temporal Server 1.29.0 <= 1.29.7
Temporal Server 1.30.0 < 1.30.7
Temporal Server 1.31.0 < 1.31.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
