Denial of Service Vulnerability in TChannel-Go by Temporal.io
CVE-2026-65652
8.7HIGH
What is CVE-2026-65652?
A vulnerability in TChannel-Go allows an unauthenticated network peer to exploit an improperly validated checksum-type field in inbound call frames. This leads to a failure in parsing, causing a panic and terminating the hosting process. Consequently, applications exposing this listener to untrusted peers are susceptible to remote denial of service, impacting availability without affecting the confidentiality or integrity of the data.
Affected Version(s)
temporalio/tchannel-go 0.0.0-20160105034737-a6904155f628 < 1.22.1-0.20260720194454-0cb017f6870a
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
An external security researcher who reported this issue responsibly to Temporal Technologies
