CVE-2025-8396

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
15/09/2025
Last modified:
15/09/2025

Description

Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.