CVE-2026-16651: Temporal Technologies, Inc Temporal Server

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by strings.IndexFunc before using it as a slice boundary. The resulting Go runtime panic propagates unless the caller recovers it on the parsing goroutine, so applications that parse attacker-controlled SQL can terminate. Temporal Server exposes the affected parser through ListWorkers. When that API is enabled, an authenticated caller with namespace read permission can submit a malformed query that terminates the receiving Matching process. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.

Affected products

  • Temporal Technologies, Inc Temporal Server: from 1.29.0, up to and including 1.29.7; from 1.30.0, before 1.30.7 (fixed in 1.30.7); from 1.31.0, before 1.31.3 (fixed in 1.31.3)
  • Temporal Technologies, Inc Temporalio/sqlparser: from 0.0.0-20180604150908-b055e9c9b4fa, before 0.0.0-20260721183040-74181ffcbaaf (fixed in 0.0.0-20260721183040-74181ffcbaaf)

Published 2026-09-21. Last modified 2026-09-22.