Affected by GO-2025-3953
and 4 other vulnerabilities
GO-2025-3953: Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling in go.temporal.io/server
GO-2025-4272: Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server
GO-2026-4273: Temporal has an Incorrect Authorization vulnerability in go.temporal.io/server
GO-2026-5578: Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server
GO-2026-5766: Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server