« Volver al listado

CVE-2026-65651

Estado: Pendiente de análisisAlta (8.7)—

temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later formats or walks the returned tree can encounter a runtime-fatal Go stack overflow that terminates the process; Go panic recovery cannot contain this condition.

Leer descripción completaMostrar menos

Temporal Server passes caller-controlled query input through the affected parser in archival, visibility, and worker-query paths. In affected validation paths, the Server recursively formats an invalid expression while constructing an error. In a supported authenticated deployment, a caller with namespace read permission can terminate the receiving Frontend or Matching process. The dynamically confirmed ListWorkers route additionally requires at least one retained worker heartbeat. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector AV:N/PR:N sin interacción permite explotación remota de parser SQL (T1190). Desbordamiento de pila causa DoS por crasheo de proceso (T1499.004), requiere autenticación en namespace pero sin privilegios elevados.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-65651",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-65651",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-21T15:30:53.004421Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "security@temporal.io",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "security@temporal.io",
      "affectedData": [
        {
          "repo": "https://github.com/temporalio/sqlparser",
          "vendor": "Temporal Technologies, Inc.",
          "modules": [
            "AST",
            "Parser"
          ],
          "product": "temporalio/sqlparser",
          "versions": [
            {
              "status": "affected",
              "version": "0.0.0-20141206041240-1aae9baceee8",
              "lessThan": "0.0.0-20260721183058-0466b6b405ac",
              "versionType": "semver"
            }
          ],
          "packageName": "github.com/temporalio/sqlparser",
          "programFiles": [
            "ast.go",
            "sql.y"
          ],
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "Parse"
            },
            {
              "name": "ParseStrictDDL"
            },
            {
              "name": "ParseNext"
            },
            {
              "name": "String"
            },
            {
              "name": "Walk"
            },
            {
              "name": "UnaryExpr.Format"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:temporal:temporal:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/temporalio/temporal",
          "vendor": "Temporal Technologies, Inc.",
          "modules": [
            "Archival",
            "Frontend",
            "Matching",
            "Visibility"
          ],
          "product": "Temporal Server",
          "versions": [
            {
              "status": "unknown",
              "version": "0.0.0",
              "lessThan": "0.10.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.10.0",
              "versionType": "semver",
              "lessThanOrEqual": "1.29.7"
            },
            {
              "status": "affected",
              "version": "1.30.0",
              "lessThan": "1.30.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.31.0",
              "lessThan": "1.31.3",
              "versionType": "semver"
            }
          ],
          "packageName": "go.temporal.io/server",
          "programFiles": [
            "common/archiver/filestore/queryParser.go",
            "common/persistence/visibility/store/query/converter.go",
            "common/persistence/visibility/store/sql/query_converter.go",
            "service/matching/workers/worker_query_engine.go"
          ],
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "queryParser.convertComparisonExpr"
            },
            {
              "name": "QueryConverter.convertComparisonExpr"
            },
            {
              "name": "comparisonExprConverter.Convert"
            },
            {
              "name": "workerQueryEngine.evaluateComparison"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-21T12:17:15.553",
  "references": [
    {
      "url": "https://github.com/temporalio/sqlparser/commit/0466b6b405accfaa781e4bef417933efc18bcaef",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/sqlparser/commit/1aae9baceee8e48525da8f56b07bf6a5ca7eb147",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/sqlparser/pull/6",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/sqlparser/pull/7",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/sqlparser/tree/v0.1.0",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/temporal/blob/v0.10.0/common/archiver/filestore/queryParser.go#L77-L132",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/temporal/pull/11202",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/temporal/releases/tag/v1.30.7",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/temporal/releases/tag/v1.31.3",
      "source": "security@temporal.io"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@temporal.io",
      "description": [
        {
          "lang": "en",
          "value": "CWE-674"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later formats or walks the returned tree can encounter a runtime-fatal Go stack overflow that terminates the process; Go panic recovery cannot contain this condition. Temporal Server passes caller-controlled query input through the affected parser in archival, visibility, and worker-query paths. In affected validation paths, the Server recursively formats an invalid expression while constructing an error. In a supported authenticated deployment, a caller with namespace read permission can terminate the receiving Frontend or Matching process. The dynamically confirmed ListWorkers route additionally requires at least one retained worker heartbeat. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified."
    }
  ],
  "lastModified": "2026-09-22T19:40:05.870",
  "sourceIdentifier": "security@temporal.io"
}