Excessive CPU Consumption in Temporal Server by Temporal Inc.
CVE-2026-16652

7.1HIGH

Key Information:

Vendor
CVE Published:
21 September 2026

What is CVE-2026-16652?

The Temporal Server suffers from an issue where an authenticated user with namespace write permission can exploit the server's scheduling mechanism. By creating or updating a Schedule that combines a fine-grained cadence with an exclusion calendar, the server is forced to evaluate candidates that are rejected by the exclusion criteria. This leads to excessive CPU usage in both Frontend and Schedule worker components. When such a persisted specification is invoked, it can cause the Schedule Workflow to fail repeatedly, resulting in continuous CPU consumption until the Schedule is deleted or the Workflow is terminated. This vulnerability primarily affects the availability of the server, as it does not compromise or alter Workflow data.

Affected Version(s)

Temporal Server 1.17.0 <= 1.29.7

Temporal Server 1.30.0 < 1.30.7

Temporal Server 1.31.0 < 1.31.3

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

An external security researcher who reported this issue responsibly to Temporal Technologies
.