Temporal Technologies Inc.

First CVE: Jun 30, 2023Active for: 3 years
9
CVEs Published
More CVEs Published than 25% of tracked CNAs
2.3
Avg CVEs / Year
More Avg CVEs / Year than 15% of tracked CNAs
4.0
Avg CVSS Score
Higher Avg CVSS Score than 1% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Temporal Technologies Inc. as a CNA, 33.3% affect products that Temporal Technologies Inc. develops as a vendor.

33.3%
66.7%
Self-reported: 3Third-party: 6

Of all the CVEs published that affect products developed by Temporal Technologies Inc., 100.0% are self-published by Temporal Technologies Inc. as a CNA.

100.0%
Self-published: 3Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by Temporal Technologies Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 30, 2023
3 years ago
Most Recent CVE
Apr 10, 2026
105 days ago

Top CVEs

All CVEs published by Temporal Technologies Inc. as a CNA, regardless of affected vendor or product.

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentic
Apr 10, 20266.325NONO
Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issu
Sep 15, 20256.921NONO
When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWor
Dec 30, 20255.319NONO
Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specifi
Jun 30, 20233.617NONO
A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation requires the
Apr 1, 20262.316NONO
When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Na
Dec 30, 20251.315NONO
Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an inva
Apr 3, 20244.415NONO
For an attacker with pre-existing access to send a signal to a workflow, the attacker can make the signal name a script that executes when a victim views that signal. The XSS is in
Apr 2, 20244.315NONO
The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module was used in a gRPC
Feb 12, 20252.012NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA9 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMedium
Attack Vector
Local2 (22.2%)
Network7 (77.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (66.7%)
High3 (33.3%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low5 (55.6%)
High2 (22.2%)
None2 (22.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Temporal Technologies Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Temporal Technologies Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs