« Volver al listado

CVE-2026-16651

Estado: Pendiente de análisisAlta (8.7)—

temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by strings.IndexFunc before using it as a slice boundary. The resulting Go runtime panic propagates unless the caller recovers it on the parsing goroutine, so applications that parse attacker-controlled SQL can terminate. Temporal Server exposes the affected parser through ListWorkers.

Leer descripción completaMostrar menos

When that API is enabled, an authenticated caller with namespace read permission can submit a malformed query that terminates the receiving Matching process. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Aplicación expuesta (Temporal Server ListWorkers API) con entrada sin validación (comentarios MySQL malformados) causa panic que termina procesos, resultando en DoS de aplicación.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-16651",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-16651",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-21T15:32:17.328992Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "security@temporal.io",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "security@temporal.io",
      "affectedData": [
        {
          "repo": "https://github.com/temporalio/sqlparser",
          "vendor": "Temporal Technologies, Inc.",
          "modules": [
            "Parser"
          ],
          "product": "temporalio/sqlparser",
          "versions": [
            {
              "status": "affected",
              "version": "0.0.0-20180604150908-b055e9c9b4fa",
              "lessThan": "0.0.0-20260721183040-74181ffcbaaf",
              "versionType": "semver"
            }
          ],
          "packageName": "github.com/temporalio/sqlparser",
          "programFiles": [
            "comments.go",
            "token.go"
          ],
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "ExtractMysqlComment"
            },
            {
              "name": "Tokenizer.scanMySQLSpecificComment"
            },
            {
              "name": "Parse"
            },
            {
              "name": "ParseStrictDDL"
            },
            {
              "name": "ParseNext"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:temporal:temporal:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/temporalio/temporal",
          "vendor": "Temporal Technologies, Inc.",
          "modules": [
            "Matching"
          ],
          "product": "Temporal Server",
          "versions": [
            {
              "status": "affected",
              "version": "1.29.0",
              "versionType": "semver",
              "lessThanOrEqual": "1.29.7"
            },
            {
              "status": "affected",
              "version": "1.30.0",
              "lessThan": "1.30.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.31.0",
              "lessThan": "1.31.3",
              "versionType": "semver"
            }
          ],
          "packageName": "go.temporal.io/server",
          "programFiles": [
            "service/matching/handler.go",
            "service/matching/workers/worker_query_engine.go"
          ],
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "Handler.ListWorkers"
            },
            {
              "name": "getWhereCause"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-21T12:17:10.167",
  "references": [
    {
      "url": "https://github.com/temporalio/sqlparser/commit/74181ffcbaaf0c52faa925f4cf27ed6c0c2be86f",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/sqlparser/pull/5",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/sqlparser/tree/v0.1.0",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/temporal/pull/11090",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/temporal/pull/11190",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/temporal/releases/tag/v1.30.7",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/temporal/releases/tag/v1.31.3",
      "source": "security@temporal.io"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@temporal.io",
      "description": [
        {
          "lang": "en",
          "value": "CWE-129"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by strings.IndexFunc before using it as a slice boundary. The resulting Go runtime panic propagates unless the caller recovers it on the parsing goroutine, so applications that parse attacker-controlled SQL can terminate. Temporal Server exposes the affected parser through ListWorkers. When that API is enabled, an authenticated caller with namespace read permission can submit a malformed query that terminates the receiving Matching process. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified."
    }
  ],
  "lastModified": "2026-09-22T19:40:05.870",
  "sourceIdentifier": "security@temporal.io"
}