MEDIUM
GHSA-p768-c3pr-6459
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling
Quick fix
GHSA-p768-c3pr-6459 — go.temporal.io/server: upgrade to the fixed version with the command below.
go get go.temporal.io/server@v1.26.3Details
Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation. This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/go.temporal.io/server
Introduced in:
1.27.0-126.0Fixed in: 1.27.3Fix
go get go.temporal.io/server@v1.27.3Go/go.temporal.io/server
Introduced in:
1.28.0-129.0Fixed in: 1.28.1Fix
go get go.temporal.io/server@v1.28.1