FlawAtlas
Search the atlas
CVE-2025-8396 Moderate

Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server

Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server

Exploit probability 0.4%
Published September 17, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

89 explicit affected versions

Go go.temporal.io/server
Go go.temporal.io/server

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-8396

Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.

View original source
Open Source Vulnerabilities GHSA-p768-c3pr-6459

Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation. This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.

View original source
Open Source Vulnerabilities GO-2025-3953

Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server

View original source

05 / REFERENCES

Further evidence