Denial of Service Vulnerability in TChannel-Go by Temporal.io
CVE-2026-65652

8.7HIGH

Key Information:

Vendor
CVE Published:
21 September 2026

What is CVE-2026-65652?

A vulnerability in TChannel-Go allows an unauthenticated network peer to exploit an improperly validated checksum-type field in inbound call frames. This leads to a failure in parsing, causing a panic and terminating the hosting process. Consequently, applications exposing this listener to untrusted peers are susceptible to remote denial of service, impacting availability without affecting the confidentiality or integrity of the data.

Affected Version(s)

temporalio/tchannel-go 0.0.0-20160105034737-a6904155f628 < 1.22.1-0.20260720194454-0cb017f6870a

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

An external security researcher who reported this issue responsibly to Temporal Technologies
.