Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p768-c3pr-6459

Опубликовано: 15 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling

Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation. This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.

Пакеты

Наименование

go.temporal.io/server

go
Затронутые версииВерсия исправления

< 1.26.3

1.26.3

Наименование

go.temporal.io/server

go
Затронутые версииВерсия исправления

>= 1.27.0-126.0, < 1.27.3

1.27.3

Наименование

go.temporal.io/server

go
Затронутые версииВерсия исправления

>= 1.28.0-129.0, < 1.28.1

1.28.1

EPSS

Процентиль: 34%
0.00135
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-770

Связанные уязвимости

nvd
5 месяцев назад

Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.

EPSS

Процентиль: 34%
0.00135
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-770