Temporal Technologies Inc.
Self-Reporting Analysis
Of all the CVEs published by Temporal Technologies Inc. as a CNA, 33.3% affect products that Temporal Technologies Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Temporal Technologies Inc., 100.0% are self-published by Temporal Technologies Inc. as a CNA.
Trends Over Time
The number and severity of CVEs published by Temporal Technologies Inc. over time
Top CVEs
All CVEs published by Temporal Technologies Inc. as a CNA, regardless of affected vendor or product.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5724MEDIUM The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentic | Apr 10, 2026 | 6.3 | 25 | NO | NO |
CVE-2025-8396MEDIUM Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issu | Sep 15, 2025 | 6.9 | 21 | NO | NO |
CVE-2025-14987MEDIUM When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWor | Dec 30, 2025 | 5.3 | 19 | NO | NO |
Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specifi | Jun 30, 2023 | 3.6 | 17 | NO | NO |
A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation requires the | Apr 1, 2026 | 2.3 | 16 | NO | NO |
When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Na | Dec 30, 2025 | 1.3 | 15 | NO | NO |
CVE-2024-2689MEDIUM Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an inva | Apr 3, 2024 | 4.4 | 15 | NO | NO |
CVE-2024-2435MEDIUM For an attacker with pre-existing access to send a signal to a workflow, the attacker can make the signal name a script that executes when a victim views that signal. The XSS is in | Apr 2, 2024 | 4.3 | 15 | NO | NO |
The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module was used in a gRPC | Feb 12, 2025 | 2.0 | 12 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (9 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Temporal Technologies Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Temporal Technologies Inc. as a CNA — matched by CVE ID, not by organization name.