{"schema_version":"1.9.0","id":"CVE-2025-8396","published":"2025-09-15T14:13:26.507Z","modified":"2026-08-12T03:51:28.023316176Z","aliases":["GHSA-p768-c3pr-6459","GO-2025-3953"],"related":["CGA-7639-fg56-q8ff","SUSE-SU-2025:03289-1","openSUSE-SU-2025:15564-1","openSUSE-SU-2026:21483-1"],"details":"Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/temporalio/temporal","events":[{"introduced":"0"},{"introduced":"b1ae42e00f5d784b66c41ac7d353ef9e55390241"},{"introduced":"b03650523460b098cbaacf97192fc45a0c48d995"},{"fixed":"2a33f1814abf0e004ec692254d6a419fb26448f9"},{"fixed":"8f6caaff6170c559dc891c3ffe84f7660cda4c69"},{"fixed":"bc2433d037b163568ed4420f70023dde1a4ae5b5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.26.3"},{"introduced":"1.27.0"},{"fixed":"1.27.3"},{"introduced":"1.28.0"},{"fixed":"1.28.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.26.2","v1.27.2","v1.28.0","v1.27.1","v1.27.0","v1.26.2-rc.2","v1.26.2-125.1","v1.26.2-rc.0","v1.26.2-125.0","v1.26.2-124.0","v1.26.2-123.0","v1.26.2-122.0","v1.26.2-121.0","v1.26.1-121.0","v1.26.0","v1.25.0-119.0","v1.26.0-120","v1.25.0-rc.1","v1.25.0-118.0","v1.25.0-117.0","v1.25.0-116.0","v1.25.0-115.0","v1.25.0-114.0","v1.25.0-113.0","v1.24.0-m3.0","v1.24.0-m2.2","v1.24.0-m2.1","v1.24.0-m1","norbert/wip","norbert-109","v1.23.0-rc2","v1.23.0-rc1","v1.23.0-rc0","v1.22.0-rc1","v1.20.0","dummy-tag","v1.18.0","v1.16.0","v1.15.0","v1.13.0","v1.12.0","v1.11.0","v1.10.0","v1.9.0","v1.8.0","v1.7.0","v1.0.0","v1.6.0","v1.5.0","v1.4.0","v1.1.0","v1.0.0-rc1","v0.31.0","v0.30.0","v.0.29.0","v0.28.0","v0.27.0","v0.26.0","v0.25.0","v0.23.1","v0.23.0","v0.21.1","v0.21.0","v0.20.0","v0.10.0","v0.8.1","v0.8.0","v0.5.5","v0.5.4","v0.5.3","v0.4.0","v0.3.15","v0.3.14","v0.3.13","v0.3.12","v0.3.11","v0.3.9","v0.3.8","v0.3.7","v0.3.6","v0.3.5","v0.3.4","v0.3.3","v0.3.2","v0.3.1","v0.3.0","v0.2.0","v0.1.1-beta","v0.1.0-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8396.json"}}],"references":[{"type":"WEB","url":"https://github.com/temporalio/temporal/releases/tag/v1.26.3"},{"type":"WEB","url":"https://github.com/temporalio/temporal/releases/tag/v1.27.3"},{"type":"WEB","url":"https://github.com/temporalio/temporal/releases/tag/v1.28.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8396.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8396"},{"type":"PACKAGE","url":"https://github.com/temporalio/temporal"}],"database_specific":{"cna_assigner":"Temporal","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8396.json"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/S:N/AU:Y"}]}