—
GO-2026-4273
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server
Quick fix
GO-2026-4273 — go.temporal.io/server: upgrade to the fixed version with the command below.
go get go.temporal.io/server@v1.27.4Details
Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: go.temporal.io/server from v1.29.0-0 before v1.29.0-135.0.0.20251218190115-b292a32bacdf.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/advisories/GHSA-hmhp-gh8m-c8xp[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-14987[ADVISORY]
- https://github.com/temporalio/temporal/commit/b292a32bacdfa6472affd90f0a940408d5839cfa[WEB]
- https://github.com/temporalio/temporal/releases/tag/v1.27.4[WEB]
- https://github.com/temporalio/temporal/releases/tag/v1.28.2[WEB]
- https://github.com/temporalio/temporal/releases/tag/v1.29.2[WEB]