Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29200 | Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted. |
Github GHSA |
GHSA-p768-c3pr-6459 | Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling |
Solution
Upgrade to a fixed release: v1.26.3, v1.27.3, v1.28.1 or later (latest recommended).
Workaround
Use mTLS, or bring your own claim mapper.
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Temporal
Temporal temporal |
|
| Vendors & Products |
Temporal
Temporal temporal |
Mon, 15 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted. | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Temporal
Published:
Updated: 2025-09-15T14:52:27.444Z
Reserved: 2025-07-30T20:55:26.996Z
Link: CVE-2025-8396
Updated: 2025-09-15T14:51:46.097Z
Status : Awaiting Analysis
Published: 2025-09-15T15:15:55.280
Modified: 2025-09-15T15:22:27.090
Link: CVE-2025-8396
No data.
OpenCVE Enrichment
Updated: 2025-09-17T10:52:25Z
EUVD
Github GHSA