{"api_version":"v1","generated_at":"2026-10-09T07:15:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-temporal-technologies-temporalio-tchannel-go-9e88e002120a","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"temporalio/tchannel-go","next_cursor":null,"observations":[{"affected":"temporalio/tchannel-go: 0.0.0-20150531204735-8d8ca17342b3 < 1.22.1-0.20260720194454-0cb017f6870a","affected_versions_present":true,"cve_id":"CVE-2026-65653","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65653","fixed":"Upgrade github.com/temporalio/tchannel-go to v1.22.1 or later. The fix rejects fragments containing no argument chunks before indexing the chunk slice.","last_modified":"2026-09-21T15:28:21.825Z","patch_url":"https://github.com/temporalio/tchannel-go/commit/8d8ca17342b3620d3a6d5c1a825145595e7588ff","primary_source":"","published":"2026-09-21T11:36:47.095Z"},{"affected":"temporalio/tchannel-go: 0.0.0-20160105034737-a6904155f628 < 1.22.1-0.20260720194454-0cb017f6870a","affected_versions_present":true,"cve_id":"CVE-2026-65652","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65652","fixed":"Upgrade github.com/temporalio/tchannel-go to v1.22.1 or later. The fix rejects unsupported checksum types during direct and relay frame parsing and prevents out-of-range checksum-pool access.","last_modified":"2026-09-21T15:30:00.325Z","patch_url":"https://github.com/temporalio/tchannel-go/commit/a6904155f628b9e602b7bc88ef489004a786f7f4","primary_source":"","published":"2026-09-21T11:35:40.896Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Temporal Technologies, Inc."}}
