Excessive CPU Consumption in Temporal Server by Temporal Inc.
CVE-2026-16652
What is CVE-2026-16652?
The Temporal Server suffers from an issue where an authenticated user with namespace write permission can exploit the server's scheduling mechanism. By creating or updating a Schedule that combines a fine-grained cadence with an exclusion calendar, the server is forced to evaluate candidates that are rejected by the exclusion criteria. This leads to excessive CPU usage in both Frontend and Schedule worker components. When such a persisted specification is invoked, it can cause the Schedule Workflow to fail repeatedly, resulting in continuous CPU consumption until the Schedule is deleted or the Workflow is terminated. This vulnerability primarily affects the availability of the server, as it does not compromise or alter Workflow data.
Affected Version(s)
Temporal Server 1.17.0 <= 1.29.7
Temporal Server 1.30.0 < 1.30.7
Temporal Server 1.31.0 < 1.31.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
