PT-2026-96074 · Temporal+1 · Temporal Server+1

CVE-2026-65651

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions temporalio/sqlparser (affected versions not specified) Temporal Server (affected versions not specified)
Description The temporalio/sqlparser library allows SQL containing deeply nested unary expressions, resulting in a deep abstract syntax tree because no nesting limit is enforced. The String and Walk operations recursively traverse this tree. When an application parses attacker-controlled SQL and subsequently formats or walks the tree, it can trigger a runtime-fatal Go stack overflow, which terminates the process and cannot be handled by Go panic recovery. Temporal Server is affected as it passes caller-controlled query input through this parser in archival, visibility, and worker-query paths. Specifically, in validation paths, the Server recursively formats invalid expressions during error construction. An authenticated user with namespace read permission can terminate the Frontend or Matching process. The ListWorkers route also requires at least one retained worker heartbeat. This can lead to a sustained denial of service affecting availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65651

Affected Products

Temporal Server
Sqlparse