VDB
Sign up
MEDIUM

GHSA-p768-c3pr-6459

Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling

Quick fix

GHSA-p768-c3pr-6459 — go.temporal.io/server: upgrade to the fixed version with the command below.

go get go.temporal.io/server@v1.26.3

Details

Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation. This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/go.temporal.io/server
Introduced in: 0Fixed in: 1.26.3
Fixgo get go.temporal.io/server@v1.26.3
Go/go.temporal.io/server
Introduced in: 1.27.0-126.0Fixed in: 1.27.3
Fixgo get go.temporal.io/server@v1.27.3
Go/go.temporal.io/server
Introduced in: 1.28.0-129.0Fixed in: 1.28.1
Fixgo get go.temporal.io/server@v1.28.1

References