PT-2025-37567 · Temporal · Temporal Server
CVE-2025-8396
·
Published
2025-09-15
·
Updated
2026-07-30
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/S:N/AU:Y |
Name of the Vulnerable Software and Affected Versions
Temporal Server versions prior to 1.26.3
Temporal Server versions prior to 1.27.3
Temporal Server versions prior to 1.28.1
Description
Insufficiently specific bounds checking on the authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.
Recommendations
Update to Temporal Server version 1.26.3 or later.
Update to Temporal Server version 1.27.3 or later.
Update to Temporal Server version 1.28.1 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Temporal Server