CVE-2026-65651
📛 CVE Title
temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow during AST traversal
Description
temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later formats or walks the returned tree can encounter a runtime-fatal Go stack overflow that terminates the process; Go panic recovery cannot contain this condition. Temporal Server passes caller-controlled query input through the affected parser in archival, visibility, and worker-query paths. In affected validation paths, the Server recursively formats an invalid expression while constructing an error. In a supported authenticated deployment, a caller with namespace read permission can terminate the receiving Frontend or Matching process. The dynamically confirmed ListWorkers route additionally requires at least one retained worker heartbeat. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Temporal
- CVSS severity
- HIGH
- CVSS score
- 8.7 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N- Effective score
- 8.7 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-674 - Reserved
- 2026-07-22
- Published
- 2026-09-21 11:34 UTC
- Last updated
- 2026-09-21 15:31 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/65xxx/CVE-2026-65651.json
- Linked Threat
- CVE-2026-65651 — temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow during AST traversal
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-21 12:17:15 UTC
- NVD last modified
- 2026-09-21 16:17:10 UTC
NVD / KEV / EPSS data refreshed 2026-09-22 03:39 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-83892 - Assigner
- Temporal
- Published
- Sep 21, 2026, 11:34:05 AM
- Updated
- Sep 21, 2026, 3:31:05 PM
- EUVD base score (CVSS 4.0)
-
8.7 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.0000
- Vendors
- Temporal Technologies, Inc.
- Products
-
Temporal Server (0.10.0 ≤1.29.7)temporalio/sqlparser (0.0.0-20141206041240-1aae9baceee8 <0.0.0-20260721183058-0466b6b405ac)Temporal Server (1.31.0 <1.31.3)Temporal Server (1.30.0 <1.30.7)
- Aliases
-
GHSA-7vcf-7m3r-v7x3
ENISA description: temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later formats or walks the returned tree can encounter a runtime-fatal Go stack overflow that terminates the process; Go panic recovery cannot contain this condition. Temporal Server passes caller-controlled query input through the affected parser in archival, visibility, and worker-query paths. In affected validation paths, the Server recursively formats an invalid expression while constructing an error. In a supported authenticated deployment, a caller with namespace read permission can terminate the receiving Frontend or Matching process. The dynamically confirmed ListWorkers route additionally requires at least one retained worker heartbeat. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.
EUVD references (9)
- https://github.com/temporalio/sqlparser/commit/1aae9baceee8e48525da8f56b07bf6a5ca7eb147
- https://github.com/temporalio/sqlparser/pull/6
- https://github.com/temporalio/sqlparser/commit/0466b6b405accfaa781e4bef417933efc18bcaef
- https://github.com/temporalio/sqlparser/tree/v0.1.0
- https://github.com/temporalio/sqlparser/pull/7
- https://github.com/temporalio/temporal/pull/11202
- https://github.com/temporalio/temporal/blob/v0.10.0/common/archiver/filestore/queryParser.go#L77-L132
- https://github.com/temporalio/temporal/releases/tag/v1.30.7
- https://github.com/temporalio/temporal/releases/tag/v1.31.3
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Temporal Technologies, Inc. | temporalio/sqlparser |
0.0.0-20141206041240-1aae9baceee8 (affected)
|
— |
| Temporal Technologies, Inc. | Temporal Server |
0.0.0 (unknown),
0.10.0 (affected),
1.30.0 (affected),
1.31.0 (affected)
|
— |
Vendor references (9)
References embedded in the original CVE record by the assigning CNA.
- First affected sqlparser source revision product
- sqlparser nested-expression fix pull request patch
- First fixed sqlparser commit patch
- Fixed release tag v0.1.0 product
- Broader sqlparser AST-depth hardening patch
- Temporal Server dependency update patch
- Temporal Server 0.10.0 source-confirmed archival route product
- Temporal Server 1.30.7 release-notes
- Temporal Server 1.31.3 release-notes
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (9)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/temporalio/sqlparser/commit/0466b6b405accfaa781e4bef417933efc18bcaef security@temporal.io
- https://github.com/temporalio/sqlparser/commit/1aae9baceee8e48525da8f56b07bf6a5ca7eb147 security@temporal.io
- https://github.com/temporalio/sqlparser/pull/6 security@temporal.io
- https://github.com/temporalio/sqlparser/pull/7 security@temporal.io
- https://github.com/temporalio/sqlparser/tree/v0.1.0 security@temporal.io
- https://github.com/temporalio/temporal/blob/v0.10.0/common/archiver/filestore/queryParser.go#L77-L132 security@temporal.io
- https://github.com/temporalio/temporal/pull/11202 security@temporal.io
- https://github.com/temporalio/temporal/releases/tag/v1.30.7 security@temporal.io
- https://github.com/temporalio/temporal/releases/tag/v1.31.3 security@temporal.io
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:dailysecurityreview.com
Microsoft confirmed CVE - 2026 -50656, a zero-day in the Defender Malware Protection Engine allowing SYSTEM-level privilege escalation, is under active exploitation with no patch currently available.
2026-09-22 16:47 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-09-22 16:47 UTC -
web:security.paloaltonetworks.com
Palo Alto Networks Security Advisory: CVE - 2026 -0251 GlobalProtect App: Local Privilege Escalation Vulnerabilities Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands ...
2026-09-22 16:47 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-22 16:47 UTC -
web:support.microsoft.com
This security update resolves vulnerabilities in Microsoft Exchange Server. To learn more about these vulnerabilities, see the following Common Vulnerabilities and Exposures ( CVE ): CVE - 2026 -62910 - Microsoft Common Vulnerabilities and Exposures CVE - 2026 -62911 - Microsoft Common Vulnerabilities and Exposures CVE - 2026 -62912 - Microsoft Common Vulnerabilities and Exposures CVE - 2026 -62913 ...
2026-09-22 16:47 UTC -
web:support.sap.com
SAP security Patch Day Bulletin This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape. On 9th of June 2026 , SAP security patch day saw the release of 15 new security notes.
2026-09-22 16:47 UTC -
web:windowsforum.com
ShieldBreak, a newly published proof of concept from the researcher known as Nightmare Eclipse, claims to bypass Microsoft's July fix for the Microsoft Defender privilege-escalation flaw CVE - 2026 -50656, better known as RoguePlanet.
2026-09-22 16:47 UTC -
web:www.oracle.com
This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.
2026-09-22 16:47 UTC -
web:www.oracle.com
Additional CVEs addressed are: The patch for CVE - 2026 -34481 also addresses CVE - 2026 -34477, CVE - 2026 -34478, CVE - 2026 -34479, and CVE - 2026 -34480. Oracle Fusion Middleware Risk Matrix This Critical Security Patch Update contains 106 new security patches for Oracle Fusion Middleware. 53 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a ...
2026-09-22 16:47 UTC -
web:www.techtimes.com
July 2026 Patch Tuesday permanently removes the Kerberos RC4 rollback registry key on July 14, leaving service accounts with RC4-only material unable to authenticate. Administrators must also ...
2026-09-22 16:47 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-65651.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-65651",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T15:30:53.004421Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T15:31:05.352Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://pkg.go.dev",
"defaultStatus": "unaffected",
"modules": [
"AST",
"Parser"
],
"packageName": "github.com/temporalio/sqlparser",
"product": "temporalio/sqlparser",
"programFiles": [
"ast.go",
"sql.y"
],
"programRoutines": [
{
"name": "Parse"
},
{
"name": "ParseStrictDDL"
},
{
"name": "ParseNext"
},
{
"name": "String"
},
{
"name": "Walk"
},
{
"name": "UnaryExpr.Format"
}
],
"repo": "https://github.com/temporalio/sqlparser",
"vendor": "Temporal Technologies, Inc.",
"versions": [
{
"lessThan": "0.0.0-20260721183058-0466b6b405ac",
"status": "affected",
"version": "0.0.0-20141206041240-1aae9baceee8",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://pkg.go.dev",
"cpes": [
"cpe:2.3:a:temporal:temporal:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"Archival",
"Frontend",
"Matching",
"Visibility"
],
"packageName": "go.temporal.io/server",
"product": "Temporal Server",
"programFiles": [
"common/archiver/filestore/queryParser.go",
"common/persistence/visibility/store/query/converter.go",
"common/persistence/visibility/store/sql/query_converter.go",
"service/matching/workers/worker_query_engine.go"
],
"programRoutines": [
{
"name": "queryParser.convertComparisonExpr"
},
{
"name": "QueryConverter.convertComparisonExpr"
},
{
"name": "comparisonExprConverter.Convert"
},
{
"name": "workerQueryEngine.evaluateComparison"
}
],
"repo": "https://github.com/temporalio/temporal",
"vendor": "Temporal Technologies, Inc.",
"versions": [
{
"lessThan": "0.10.0",
"status": "unknown",
"version": "0.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "1.29.7",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"lessThan": "1.30.7",
"status": "affected",
"version": "1.30.0",
"versionType": "semver"
},
{
"lessThan": "1.31.3",
"status": "affected",
"version": "1.31.0",
"versionType": "semver"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>The temporalio/sqlparser CVSS scenario uses the reasonable worst case of a network service passing unauthenticated attacker-controlled SQL to the parser and then invoking String or Walk on the resulting AST. Applications that embed the library should reassess the vector for their actual input and privilege boundaries.</p>"
}
],
"value": "The temporalio/sqlparser CVSS scenario uses the reasonable worst case of a network service passing unauthenticated attacker-controlled SQL to the parser and then invoking String or Walk on the resulting AST. Applications that embed the library should reassess the vector for their actual input and privilege boundaries."
},
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>The known affected Temporal Server lower bound is 0.10.0, based on a source-confirmed built-in filestore visibility-archival query path; earlier Server releases are unknown. Additional source-confirmed SQL and Elasticsearch visibility paths begin in later releases. These routes do not require retained worker state. Their availability depends on the deployed visibility or archival configuration, which CVSS Base scoring assumes is enabled when assessing the vulnerable configuration.</p>"
}
],
"value": "The known affected Temporal Server lower bound is 0.10.0, based on a source-confirmed built-in filestore visibility-archival query path; earlier Server releases are unknown. Additional source-confirmed SQL and Elasticsearch visibility paths begin in later releases. These routes do not require retained worker state. Their availability depends on the deployed visibility or archival configuration, which CVSS Base scoring assumes is enabled when assessing the vulnerable configuration."
},
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>The dynamically confirmed Temporal Server ListWorkers route begins in 1.29.0. In 1.29.x, frontend.ListWorkersEnabled defaults to false; it defaults to true in 1.30.x. Beginning in 1.31.0, the setting remains defined but is no longer honored, and ListWorkers is always enabled. In supported authenticated deployments, ListWorkers requires namespace read permission. The confirmed process-exit route also requires at least one retained worker heartbeat.</p>"
}
],
"value": "The dynamically confirmed Temporal Server ListWorkers route begins in 1.29.0. In 1.29.x, frontend.ListWorkersEnabled defaults to false; it defaults to true in 1.30.x. Beginning in 1.31.0, the setting remains defined but is no longer honored, and ListWorkers is always enabled. In supported authenticated deployments, ListWorkers requires namespace read permission. The confirmed process-exit route also requires at least one retained worker heartbeat."
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "An external security researcher who reported this issue responsibly to Temporal Technologies"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later formats or walks the returned tree can encounter a runtime-fatal Go stack overflow that terminates the process; Go panic recovery cannot contain this condition. Temporal Server passes caller-controlled query input through the affected parser in archival, visibility, and worker-query paths. In affected validation paths, the Server recursively formats an invalid expression while constructing an error. In a supported authenticated deployment, a caller with namespace read permission can terminate the receiving Frontend or Matching process. The dynamically confirmed ListWorkers route additionally requires at least one retained worker heartbeat. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.</p>"
}
],
"value": "temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later formats or walks the returned tree can encounter a runtime-fatal Go stack overflow that terminates the process; Go panic recovery cannot contain this condition. Temporal Server passes caller-controlled query input through the affected parser in archival, visibility, and worker-query paths. In affected validation paths, the Server recursively formats an invalid expression while constructing an error. In a supported authenticated deployment, a caller with namespace read permission can terminate the receiving Frontend or Matching process. The dynamically confirmed ListWorkers route additionally requires at least one retained worker heartbeat. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified."
}
],
"impacts": [
{
"descriptions": [
{
"lang": "en",
"value": "Denial of service caused by runtime-fatal Go stack exhaustion and process termination. No confidentiality or integrity impact was identified."
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "temporalio/sqlparser reasonable worst-case network service embedding"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "Temporal Server visibility or archival query path in a supported authenticated deployment"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "Dynamically confirmed Temporal Server ListWorkers path with retained worker state"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674: Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T11:34:05.930Z",
"orgId": "61241ed8-fa44-4f23-92db-b8c443751968",
"shortName": "Temporal"
},
"references": [
{
"name": "First affected sqlparser source revision",
"tags": [
"product"
],
"url": "https://github.com/temporalio/sqlparser/commit/1aae9baceee8e48525da8f56b07bf6a5ca7eb147"
},
{
"name": "sqlparser nested-expression fix pull request",
"tags": [
"patch"
],
"url": "https://github.com/temporalio/sqlparser/pull/6"
},
{
"name": "First fixed sqlparser commit",
"tags": [
"patch"
],
"url": "https://github.com/temporalio/sqlparser/commit/0466b6b405accfaa781e4bef417933efc18bcaef"
},
{
"name": "Fixed release tag v0.1.0",
"tags": [
"product"
],
"url": "https://github.com/temporalio/sqlparser/tree/v0.1.0"
},
{
"name": "Broader sqlparser AST-depth hardening",
"tags": [
"patch"
],
"url": "https://github.com/temporalio/sqlparser/pull/7"
},
{
"name": "Temporal Server dependency update",
"tags": [
"patch"
],
"url": "https://github.com/temporalio/temporal/pull/11202"
},
{
"name": "Temporal Server 0.10.0 source-confirmed archival route",
"tags": [
"product"
],
"url": "https://github.com/temporalio/temporal/blob/v0.10.0/common/archiver/filestore/queryParser.go#L77-L132"
},
{
"name": "Temporal Server 1.30.7",
"tags": [
"release-notes"
],
"url": "https://github.com/temporalio/temporal/releases/tag/v1.30.7"
},
{
"name": "Temporal Server 1.31.3",
"tags": [
"release-notes"
],
"url": "https://github.com/temporalio/temporal/releases/tag/v1.31.3"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>Upgrade github.com/temporalio/sqlparser to v0.0.0-20260721183058-0466b6b405ac or later; v0.0.0-20260722001706-17d16cfe1da5 is the preferred upgrade. Temporal Server operators should upgrade to 1.30.7, 1.31.3, or 1.32.0, as appropriate for the deployed minor release line. The parser changes reject excessive nesting before recursive AST consumers receive an attacker-deep tree.</p>"
}
],
"value": "Upgrade github.com/temporalio/sqlparser to v0.0.0-20260721183058-0466b6b405ac or later; v0.0.0-20260722001706-17d16cfe1da5 is the preferred upgrade. Temporal Server operators should upgrade to 1.30.7, 1.31.3, or 1.32.0, as appropriate for the deployed minor release line. The parser changes reject excessive nesting before recursive AST consumers receive an attacker-deep tree."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow during AST traversal",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>Applications can impose a conservative query-size or nesting limit before parsing and avoid recursively formatting or walking parser-produced trees derived from untrusted input. Temporal Server 1.29 and 1.30 operators can disable ListWorkers when it is unused, disable unused archival reads, and restrict namespace read permission to trusted principals. Go panic recovery is not an effective mitigation for runtime-fatal stack overflow.</p>"
}
],
"value": "Applications can impose a conservative query-size or nesting limit before parsing and avoid recursively formatting or walking parser-produced trees derived from untrusted input. Temporal Server 1.29 and 1.30 operators can disable ListWorkers when it is unused, disable unused archival reads, and restrict namespace read permission to trusted principals. Go panic recovery is not an effective mitigation for runtime-fatal stack overflow."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "61241ed8-fa44-4f23-92db-b8c443751968",
"assignerShortName": "Temporal",
"cveId": "CVE-2026-65651",
"datePublished": "2026-09-21T11:34:05.930Z",
"dateReserved": "2026-07-22T18:08:48.925Z",
"dateUpdated": "2026-09-21T15:31:05.352Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}