Parsing Vulnerability in Temporal Server by Temporal.io
CVE-2026-16651

7.1HIGH

What is CVE-2026-16651?

A vulnerability exists within the SQL parser of Temporal Server that could lead to a panic in the Go runtime when processing malformed MySQL version comments. If these comments are empty or consist solely of one to five decimal digits, the parser may fail to handle the response appropriately. This flaw allows an authenticated user with read permission to cause a denial-of-service condition by submitting a crafted query, which can crash the matching process of the server. The issue, while impacting availability, does not affect data confidentiality or integrity, making it crucial for developers to implement recovery strategies to prevent service interruptions.

Affected Version(s)

Temporal Server 1.29.0 <= 1.29.7

Temporal Server 1.30.0 < 1.30.7

Temporal Server 1.31.0 < 1.31.3

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

An external security researcher who reported this issue responsibly to Temporal Technologies
.