Affected by GO-2026-5578
and 1 other vulnerabilities
GO-2026-5578: Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint in go.temporal.io/server
GO-2026-5766: Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster in go.temporal.io/server