Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY5 SECURITY RECORDS

Temporal Technologies, Inc.

Temporal Server

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-89139 21 Sep 2026 Temporal Server: 1.31.0 < 1.31.3 Upgrade to Temporal Server 1.32.0 or 1.31.3. Both pin a Worker Controller Instance module revision whose compute provider allowlist denies by default instead of permitting every registered provider. Operators who cannot upgrade immediately can apply the workaround below, which closes the same path without waiting for a release. The 1.30 release line does not depend on the Worker Controller Instance module at all and is unaffected. Note that the change shipped in 1.32.0 and 1.31.3 makes the allowlist deny by default and does not change where the executed command comes from: for a compute provider an operator does deliberately add to the allowlist, the program name and argument vector still arrive in the caller's request. Update reference ↗
CVE-2026-87858 21 Sep 2026 Temporal Server: 1.30.0 < 1.30.7, 1.31.0 < 1.31.3, 1.25.0 ≤ 1.29.7 Upgrade to Temporal Server 1.32.0, which ships callback.inspectSourceHeader set to false and needs no further change. The fix makes the completion-callback source header opt-in behind the callback.inspectSourceHeader setting, so a callback's internality is decided from the server-generated callback URL rather than from a caller-supplied header. Releases 1.30.7 and 1.31.3 carry the same code but ship callback.inspectSourceHeader set to true for mixed-version compatibility while callbacks created with the older callback URL template drain, and while it is true the routing behavior matches the affected releases; an operator upgrading within the 1.30 or 1.31 line must therefore also set callback.inspectSourceHeader to false once every pre-fix server has drained. Operators who set callback.inspectSourceHeader to true restore the pre-fix behavior in full, including preservation of the caller's path and query across the internal rewrite, and should not enable it on a cluster that accepts caller-supplied completion callbacks. Temporal Server releases in the 1.25.0 through 1.29.7 range are outside the supported window and receive no fix; operators on those releases should upgrade to a supported line. Update reference ↗
CVE-2026-16652 21 Sep 2026 Temporal Server: 1.17.0 ≤ 1.29.7, 1.30.0 < 1.30.7, 1.31.0 < 1.31.3 Upgrade to Temporal Server 1.30.7, 1.31.3, or 1.32.0, as appropriate for the deployed minor release line, and retain a positive scheduler.specMaxIterations value. The fix bounds the number of excluded candidates evaluated by each next-action search and stops the search with an error when the bound is reached. Review and replace or remove Schedule specifications that exceed the configured bound. Setting scheduler.specMaxIterations to zero or a negative value disables the hard bound. Update reference ↗
CVE-2024-2689 3 Apr 2024 < 1.20.5; 1.21.0 < 1.21.6; 1.22.0 < 1.22.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-3485 30 Jun 2023 1.9.1 < 1.20 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.