{"api_version":"v1","generated_at":"2026-10-08T15:55:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-temporal-technologies-temporalio-ringpop-go-633d66e665e3","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"temporalio/ringpop-go","next_cursor":null,"observations":[{"affected":"temporalio/ringpop-go: 0.0.0-20160824133849-d0de5fe13330 < 0.0.0-20260724173031-c317effcdc8b","affected_versions_present":true,"cve_id":"CVE-2026-65654","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65654","fixed":"Upgrade github.com/temporalio/ringpop-go to v0.1.0 or later. The fix validates peer-supplied label maps against the configured LabelOptions before labels are retained or disseminated. Invalid incoming labels are discarded while the remaining membership change can still be processed.","last_modified":"2026-09-21T15:26:44.632Z","patch_url":"https://github.com/temporalio/ringpop-go/commit/d0de5fe1333074d5c41a88e9053592e39f495bb2","primary_source":"","published":"2026-09-21T11:38:23.307Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Temporal Technologies, Inc."}}
