Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.
Fixes

Solution

Upgrade to a fixed release: v1.26.3, v1.27.3, v1.28.1 or later (latest recommended).


Workaround

Use mTLS, or bring your own claim mapper.

History

Mon, 15 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Sep 2025 14:30:00 +0000

Type Values Removed Values Added
Description Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/S:N/AU:Y'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Temporal

Published:

Updated: 2025-09-15T14:52:27.444Z

Reserved: 2025-07-30T20:55:26.996Z

Link: CVE-2025-8396

cve-icon Vulnrichment

Updated: 2025-09-15T14:51:46.097Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-15T15:15:55.280

Modified: 2025-09-15T15:22:27.090

Link: CVE-2025-8396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.