GO-2025-4272

Source
https://pkg.go.dev/vuln/GO-2025-4272
Import Source
https://vuln.go.dev/ID/GO-2025-4272.json
JSON Data
https://api.osv.dev/v1/vulns/GO-2025-4272
Aliases
Related
Published
2026-01-12T17:39:39Z
Modified
2026-02-04T02:24:48.615001Z
Summary
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server
Details

Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server

Database specific
{
    "review_status": "UNREVIEWED",
    "url": "https://pkg.go.dev/vuln/GO-2025-4272"
}
References

Affected packages

Go / go.temporal.io/server

Package

Name
go.temporal.io/server
View open source insights on deps.dev
Purl
pkg:golang/go.temporal.io/server

Affected ranges

Type
SEMVER
Events
Introduced
1.24.0
Fixed
1.27.4
Introduced
1.28.0
Fixed
1.28.2
Introduced
1.29.0
Fixed
1.29.2

Database specific

source
"https://vuln.go.dev/ID/GO-2025-4272.json"