go.temporal.io/server
Go7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting go.temporal.io/serverpage 1 of 1
- CVE-2023-3485LOWCVSS 3.0EG 3.0✓ Fixed in 1.20.02023-06-30
Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specified in the request. Creation of this task token must be done…
- CVE-2024-2689MEDIUMCVSS 4.4EG 4.4✓ Fixed in 1.22.72024-04-03
Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an invalid UTF-8 string for submission to potentially cause a cras…
- CVE-2025-14986LOWCVSS 1.3EG 0.0✓ Fixed in 1.29.22025-12-30
When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMult…
- CVE-2025-14987MEDIUMCVSS 5.3EG 0.0✓ Fixed in 1.29.22025-12-30
When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWorkflowExecution, RequestCancelExternalWorkflowExecution) to …
- CVE-2025-8396MEDIUMCVSS 6.9EG 0.0✓ Fixed in 1.28.12025-09-15
Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to…
- CVE-2026-5199LOWCVSS 2.3EG 0.0✓ Fixed in 1.29.52026-04-01
A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation requires the attacker to know or guess specific victim workflow ID(s) an…
- CVE-2026-5724MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.30.42026-04-10
The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminServic…
Check whether go.temporal.io/server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for go.temporal.io/server CVEs against the assets you own.
Start Free Scan →