go.temporal.io/server
Activity
- Latest release
- Jul 21, 2026
- Total releases
- 42
- Cadence
- ~31 days
- Last 12 months
- 14
Details
- First release
- Jun 30, 2017
| Version | Released | |
|---|---|---|
v1.32.0-158.7
pre
|
v1.32.0-158.7
pre
Dependencies (77)
+ 69 more |
|
v1.32.0-158.6
pre
|
v1.32.0-158.6
pre
Dependencies (77)
+ 69 more |
|
v1.32.0-159.3
pre
|
v1.32.0-159.3
pre
Dependencies (78)
+ 70 more |
|
v1.32.0-156.5
pre
|
v1.32.0-156.5
pre
Dependencies (75)
+ 67 more |
|
v1.32.0-155.0
pre
|
v1.32.0-155.0
pre
Dependencies (75)
+ 67 more |
|
v1.30.4
minor
|
v1.30.4
minor
Dependencies (69)
+ 61 more |
|
v1.31.0-152.5
pre
|
v1.31.0-152.5
pre
Dependencies (70)
+ 62 more |
|
v1.31.0-152.1
pre
|
v1.31.0-152.1
pre
Dependencies (70)
+ 62 more |
|
v1.30.0-148.5
pre
2 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.30.0-148.5
pre
Dependencies (69)
+ 61 more |
|
v1.30.0-147.7
pre
2 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.30.0-147.7
pre
Dependencies (69)
+ 61 more |
|
v1.30.0-145.4
pre
2 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.30.0-145.4
pre
Dependencies (70)
+ 62 more |
|
v1.30.0-147.1
pre
2 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.30.0-147.1
pre
Dependencies (69)
+ 61 more |
|
v1.30.0-144.0
pre
2 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.30.0-144.0
pre
Dependencies (70)
+ 62 more |
|
v1.29.0-140.3
pre
2 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.29.0-140.3
pre
Dependencies (72)
+ 64 more |
|
v1.28.0-133.5
pre
3 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.28.0-133.5
pre
Dependencies (71)
+ 63 more |
|
v1.28.0-133.4
pre
3 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.28.0-133.4
pre
Dependencies (71)
+ 63 more |
|
v1.28.0-132.0
pre
3 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.28.0-132.0
pre
Dependencies (71)
+ 63 more |
|
v1.27.0-127.0
pre
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-14986
GO-2025-4272
GHSA-p2gr-hm8g-q772
Jan 12, 2026
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.27.0-127.0
pre
Dependencies (69)
+ 61 more |
|
v1.26.2-121.4
pre
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-14986
GO-2025-4272
GHSA-p2gr-hm8g-q772
Jan 12, 2026
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.26.2-121.4
pre
Dependencies (68)
+ 60 more |
|
v1.26.0
minor
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-14986
GO-2025-4272
GHSA-p2gr-hm8g-q772
Jan 12, 2026
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.26.0
minor
Dependencies (68)
+ 60 more |
|
v1.26.0-120.3
pre
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-14986
GO-2025-4272
GHSA-p2gr-hm8g-q772
Jan 12, 2026
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.26.0-120.3
pre
Dependencies (68)
+ 60 more |
|
v1.26.0-120.1
pre
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-14986
GO-2025-4272
GHSA-p2gr-hm8g-q772
Jan 12, 2026
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.26.0-120.1
pre
Dependencies (68)
+ 60 more |
|
v1.26.0-120
pre
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-14986
GO-2025-4272
GHSA-p2gr-hm8g-q772
Jan 12, 2026
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.26.0-120
pre
Dependencies (68)
+ 60 more |
|
v1.25.0-rc.1
pre
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-14986
GO-2025-4272
GHSA-p2gr-hm8g-q772
Jan 12, 2026
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.25.0-rc.1
pre
Dependencies (68)
+ 60 more |
|
v1.25.0-114.7
pre
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-14986
GO-2025-4272
GHSA-p2gr-hm8g-q772
Jan 12, 2026
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.25.0-114.7
pre
Dependencies (69)
+ 61 more |
|
v1.24.0-m112.5
pre
4 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.24.0-m112.5
pre
Dependencies (68)
+ 60 more |
|
v1.24.0-m3.5
pre
4 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.24.0-m3.5
pre
Dependencies (68)
+ 60 more |
|
v1.24.0-m2.2
pre
4 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.24.0-m2.2
pre
Dependencies (66)
+ 58 more |
|
v1.24.0-m1
pre
4 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.24.0-m1
pre
Dependencies (64)
+ 56 more |
|
v1.23.0-rc13
pre
4 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.23.0-rc13
pre
Dependencies (64)
+ 56 more |
|
v1.22.6
minor
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.22.6
minor
Dependencies (64)
+ 56 more |
|
v1.23.0-rc5.1
pre
4 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.23.0-rc5.1
pre
Dependencies (64)
+ 56 more |
|
v1.21.5-rc3
pre
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.21.5-rc3
pre
Dependencies (64)
+ 56 more |
|
v1.21.3
minor
5 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.21.3
minor
Dependencies (63)
+ 55 more |
|
v1.15.0
minor
6 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3485
GO-2023-1879
BIT-temporal-2023-3485
GHSA-gm2g-2xr9-pxxj
Aug 20, 2024
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.15.0
minor
Dependencies (57)
+ 49 more |
|
v1.11.1
minor
6 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3485
GO-2023-1879
BIT-temporal-2023-3485
GHSA-gm2g-2xr9-pxxj
Aug 20, 2024
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.1
minor
Dependencies (53)
+ 45 more |
|
v1.6.7
minor
6 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3485
GO-2023-1879
BIT-temporal-2023-3485
GHSA-gm2g-2xr9-pxxj
Aug 20, 2024
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.6.7
minor
Dependencies (55)
+ 47 more |
|
v1.0.1
major
6 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3485
GO-2023-1879
BIT-temporal-2023-3485
GHSA-gm2g-2xr9-pxxj
Aug 20, 2024
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.1
major
Dependencies (48)
+ 40 more |
|
v1.1.0
minor
6 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3485
GO-2023-1879
BIT-temporal-2023-3485
GHSA-gm2g-2xr9-pxxj
Aug 20, 2024
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (49)
+ 41 more |
|
v0.9.4
minor
6 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3485
GO-2023-1879
BIT-temporal-2023-3485
GHSA-gm2g-2xr9-pxxj
Aug 20, 2024
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.9.4
minor
Dependencies (42)
+ 34 more |
|
v0.3.2
minor
6 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3485
GO-2023-1879
BIT-temporal-2023-3485
GHSA-gm2g-2xr9-pxxj
Aug 20, 2024
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.3.2
minor
|
|
v0.2.0
initial
6 CVEs
CVE-2026-5199
GO-2026-5766
GHSA-xpg8-3hhp-p7w8
Jun 25, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server Fixed in
1.29.5
1.30.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-5724
GO-2026-5578
GHSA-q98v-9f9w-f49q
Jun 25, 2026
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server Fixed in
1.28.4
1.29.6
1.30.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14987
GO-2026-4273
GHSA-hmhp-gh8m-c8xp
Jan 14, 2026
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf. Fixed in
1.27.4
1.28.2
1.29.2
References
Updated Jan 14, 2026 · Source: OSV.dev
CVE-2025-8396
GO-2025-3953
GHSA-p768-c3pr-6459
Sep 17, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server Fixed in
1.26.3
1.27.3
1.28.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3485
GO-2023-1879
BIT-temporal-2023-3485
GHSA-gm2g-2xr9-pxxj
Aug 20, 2024
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource in go.temporal.io/server Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2689
GO-2024-2689
GHSA-wmxc-v39r-p9wf
Jun 04, 2024
Temporal Server Denial of Service in go.temporal.io/server Temporal Server Denial of Service in go.temporal.io/server Fixed in
1.20.5
1.21.6
1.22.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.2.0
initial
|