go.temporal.io/server vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-5724Mediumgo.temporal.io/server: Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpointCVE-2026-5199Lowgo.temporal.io/server: Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same…CVE-2025-14986Lowgo.temporal.io/server: Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contextsCVE-2025-14987Mediumgo.temporal.io/server: Temporal has an Incorrect Authorization vulnerabilityCVE-2025-8396Mediumgo.temporal.io/server: Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or ThrottlingCVE-2023-3485Lowgo.temporal.io/server: Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource

Stop the waste.
Protect your environment with Kodem.