CVE-2025-8396

EPSS 0.14%

Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling

Published: 9/15/2025Modified: 2/4/2026
Also known as:GHSA-p768-c3pr-6459CGA-7639-fg56-q8ffGO-2025-3953

Description

Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation. This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

References (6)