temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later formats or walks the returned tree can encounter a runtime-fatal Go stack overflow that terminates the process; Go panic recovery cannot contain this condition. Temporal Server passes caller-controlled query input through the affected parser in archival, visibility, and worker-query paths. In affected validation paths, the Server recursively formats an invalid expression while constructing an error. In a supported authenticated deployment, a caller with namespace read permission can terminate the receiving Frontend or Matching process. The dynamically confirmed ListWorkers route additionally requires at least one retained worker heartbeat. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.
{
"cna_assigner": "Temporal",
"cwe_ids": [
"CWE-674"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65651.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.0.0-20141206041240-1aae9baceee8"
},
{
"fixed": "0.0.0-20260721183058-0466b6b405ac"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"source": "REFERENCES"
}
{
"extracted_events": [
{
"introduced": "0.10.0"
},
{
"last_affected": "1.29.7"
},
{
"introduced": "1.30.0"
},
{
"fixed": "1.30.7"
},
{
"introduced": "1.31.0"
},
{
"fixed": "1.31.3"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}