Temporal Technologies, Inc. has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 8. The median CVSS is 8.7 (high). None have a confirmed exploitation report. The most common weakness class is CWE-129 (3). Most affected products: go.temporal.io/server (3), github.com/temporalio/sqlparser (2), github.com/temporalio/tchannel-go (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.7
- Publish → KEV
- —
- Last 90 days
- 8 prev 0
Weakness classes
Products
- go.temporal.io/server 3
- github.com/temporalio/sqlparser 2
- github.com/temporalio/tchannel-go 2
- github.com/temporalio/ringpop-go 1
Worst active — by depth score
CVE-2026-89139High· 8.7Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Work…48CVE-2026-65654High· 8.7github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes48CVE-2026-65653High· 8.7github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks48CVE-2026-65652High· 8.7github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames48CVE-2026-65651High· 8.7temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit48
Temporal Technologies, Inc. vulnerabilities
CVEs affecting Temporal Technologies, Inc., newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-89139High· 8.7Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Work…
Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Work…
CVE-2026-87858High· 7.2Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header
Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose UR…
CVE-2026-65654High· 8.7github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes
github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes. A network pe…
CVE-2026-65653High· 8.7github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks
github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then unconditionally selected the first elem…
CVE-2026-65652High· 8.7github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames
github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard initialization handshake and send a call request with…
CVE-2026-65651High· 8.7temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit
temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively tr…
CVE-2026-16651High· 8.7temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits
temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned b…
CVE-2026-16652High· 7.1Temporal Server did not bound the work performed while searching for a Schedule's next action time
Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create or update a Schedule that combines a fine-grained cadence with an ex…