PT-2026-96074 · Temporal+1 · Temporal Server+1
CVE-2026-65651
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
temporalio/sqlparser (affected versions not specified)
Temporal Server (affected versions not specified)
Description
The
temporalio/sqlparser library allows SQL containing deeply nested unary expressions, resulting in a deep abstract syntax tree because no nesting limit is enforced. The String and Walk operations recursively traverse this tree. When an application parses attacker-controlled SQL and subsequently formats or walks the tree, it can trigger a runtime-fatal Go stack overflow, which terminates the process and cannot be handled by Go panic recovery. Temporal Server is affected as it passes caller-controlled query input through this parser in archival, visibility, and worker-query paths. Specifically, in validation paths, the Server recursively formats invalid expressions during error construction. An authenticated user with namespace read permission can terminate the Frontend or Matching process. The ListWorkers route also requires at least one retained worker heartbeat. This can lead to a sustained denial of service affecting availability.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Temporal Server
Sqlparse