CVE-2026-65651
temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later formats or walks the returned tree can encounter a runtime-fatal Go stack overflow that terminates the process; Go panic recovery cannot contain this condition.
Leer descripción completaMostrar menos
Temporal Server passes caller-controlled query input through the affected parser in archival, visibility, and worker-query paths. In affected validation paths, the Server recursively formats an invalid expression while constructing an error. In a supported authenticated deployment, a caller with namespace read permission can terminate the receiving Frontend or Matching process. The dynamically confirmed ListWorkers route additionally requires at least one retained worker heartbeat. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.67%
- Percentil entre todas las CVEs puntuadas: 50
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access90 % - Impacto principal
T1499.004Application or System Exploitationimpact85 %
Vector AV:N/PR:N sin interacción permite explotación remota de parser SQL (T1190). Desbordamiento de pila causa DoS por crasheo de proceso (T1499.004), requiere autenticación en namespace pero sin privilegios elevados.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-674
Referencias
- https://github.com/temporalio/sqlparser/commit/0466b6b405accfaa781e4bef417933efc18bcaef
- https://github.com/temporalio/sqlparser/commit/1aae9baceee8e48525da8f56b07bf6a5ca7eb147
- https://github.com/temporalio/sqlparser/pull/6
- https://github.com/temporalio/sqlparser/pull/7
- https://github.com/temporalio/sqlparser/tree/v0.1.0
- https://github.com/temporalio/temporal/blob/v0.10.0/common/archiver/filestore/queryParser.go#L77-L132
- https://github.com/temporalio/temporal/pull/11202
- https://github.com/temporalio/temporal/releases/tag/v1.30.7
- https://github.com/temporalio/temporal/releases/tag/v1.31.3
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-65651",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-65651",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-21T15:30:53.004421Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security@temporal.io",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security@temporal.io",
"affectedData": [
{
"repo": "https://github.com/temporalio/sqlparser",
"vendor": "Temporal Technologies, Inc.",
"modules": [
"AST",
"Parser"
],
"product": "temporalio/sqlparser",
"versions": [
{
"status": "affected",
"version": "0.0.0-20141206041240-1aae9baceee8",
"lessThan": "0.0.0-20260721183058-0466b6b405ac",
"versionType": "semver"
}
],
"packageName": "github.com/temporalio/sqlparser",
"programFiles": [
"ast.go",
"sql.y"
],
"collectionURL": "https://pkg.go.dev",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "Parse"
},
{
"name": "ParseStrictDDL"
},
{
"name": "ParseNext"
},
{
"name": "String"
},
{
"name": "Walk"
},
{
"name": "UnaryExpr.Format"
}
]
},
{
"cpes": [
"cpe:2.3:a:temporal:temporal:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/temporalio/temporal",
"vendor": "Temporal Technologies, Inc.",
"modules": [
"Archival",
"Frontend",
"Matching",
"Visibility"
],
"product": "Temporal Server",
"versions": [
{
"status": "unknown",
"version": "0.0.0",
"lessThan": "0.10.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "0.10.0",
"versionType": "semver",
"lessThanOrEqual": "1.29.7"
},
{
"status": "affected",
"version": "1.30.0",
"lessThan": "1.30.7",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.31.0",
"lessThan": "1.31.3",
"versionType": "semver"
}
],
"packageName": "go.temporal.io/server",
"programFiles": [
"common/archiver/filestore/queryParser.go",
"common/persistence/visibility/store/query/converter.go",
"common/persistence/visibility/store/sql/query_converter.go",
"service/matching/workers/worker_query_engine.go"
],
"collectionURL": "https://pkg.go.dev",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "queryParser.convertComparisonExpr"
},
{
"name": "QueryConverter.convertComparisonExpr"
},
{
"name": "comparisonExprConverter.Convert"
},
{
"name": "workerQueryEngine.evaluateComparison"
}
]
}
]
}
],
"published": "2026-09-21T12:17:15.553",
"references": [
{
"url": "https://github.com/temporalio/sqlparser/commit/0466b6b405accfaa781e4bef417933efc18bcaef",
"source": "security@temporal.io"
},
{
"url": "https://github.com/temporalio/sqlparser/commit/1aae9baceee8e48525da8f56b07bf6a5ca7eb147",
"source": "security@temporal.io"
},
{
"url": "https://github.com/temporalio/sqlparser/pull/6",
"source": "security@temporal.io"
},
{
"url": "https://github.com/temporalio/sqlparser/pull/7",
"source": "security@temporal.io"
},
{
"url": "https://github.com/temporalio/sqlparser/tree/v0.1.0",
"source": "security@temporal.io"
},
{
"url": "https://github.com/temporalio/temporal/blob/v0.10.0/common/archiver/filestore/queryParser.go#L77-L132",
"source": "security@temporal.io"
},
{
"url": "https://github.com/temporalio/temporal/pull/11202",
"source": "security@temporal.io"
},
{
"url": "https://github.com/temporalio/temporal/releases/tag/v1.30.7",
"source": "security@temporal.io"
},
{
"url": "https://github.com/temporalio/temporal/releases/tag/v1.31.3",
"source": "security@temporal.io"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "security@temporal.io",
"description": [
{
"lang": "en",
"value": "CWE-674"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later formats or walks the returned tree can encounter a runtime-fatal Go stack overflow that terminates the process; Go panic recovery cannot contain this condition. Temporal Server passes caller-controlled query input through the affected parser in archival, visibility, and worker-query paths. In affected validation paths, the Server recursively formats an invalid expression while constructing an error. In a supported authenticated deployment, a caller with namespace read permission can terminate the receiving Frontend or Matching process. The dynamically confirmed ListWorkers route additionally requires at least one retained worker heartbeat. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified."
}
],
"lastModified": "2026-09-22T19:40:05.870",
"sourceIdentifier": "security@temporal.io"
}