Skip to content
temporalGHSA-wmxc-v39r-p9wf

Temporal Server Denial of Service

Medium4.4CVE-2024-2689 · Published Apr 4, 2024 · updated Feb 28, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/temporalio/temporal
Go
>= 1.22.0-rc1, < 1.22.71.22.7
>= 1.21.0, < 1.21.61.21.6
< 1.20.51.20.5
Details and references

Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an invalid UTF-8 string for submission to potentially cause a crashloop. If left unchecked, the task containing the invalid UTF-8 will become stuck in the queue, causing an increase in queue lag. Eventually, all processes handling these queues will become stuck and the system will run out of resources. The workflow ID of the failing task will be visible in the logs, and can be used to remove that workflow as a mitigation. Version 1.23 is not impacted. In this context, a user is an operator of Temporal Server.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20
Also known as
CVE-2024-2689, GO-2024-2689

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.