CVE-2026-16651: CWE-129: Improper Validation of Array Index in Temporal Technologies, Inc. temporalio/sqlparser
CVE-2026-16651 is a high-severity vulnerability in Temporal Technologies, Inc.'s temporalio/sqlparser. The parser can panic when processing a MySQL version comment that is empty or contains only one to five decimal digits due to improper validation of array indices. This leads to a Go runtime panic that can terminate the parsing goroutine. Temporal Server exposes this parser through the ListWorkers API, allowing an authenticated user with namespace read permission to submit malformed queries that cause the Matching process to terminate. Repeated exploitation can cause a denial of service. The vulnerability affects availability only, with no impact on confidentiality or integrity.
AI Analysis
Technical Summary
The temporalio/sqlparser component improperly validates array indices when parsing MySQL version comments. Specifically, the ExtractMysqlComment function uses the result of strings.IndexFunc without checking for a -1 return value, leading to out-of-bounds slice operations and a runtime panic in Go. This panic propagates unless recovered by the caller. Temporal Server exposes this parser via the ListWorkers API, which when enabled, allows authenticated users with namespace read permission to send malformed SQL queries that cause the Matching process to crash. This can be exploited repeatedly to sustain a denial of service condition. No confidentiality or integrity impacts are reported.
Potential Impact
The vulnerability causes denial of service by crashing the Matching process in Temporal Server when parsing malformed SQL queries. It affects availability only. There is no known impact on confidentiality or integrity. Exploitation requires authentication with namespace read permission and the ListWorkers API to be enabled.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the ListWorkers API to trusted users only and monitor for abnormal termination of the Matching process. Applications should implement recovery mechanisms for panics in parsing goroutines if possible.
CVE-2026-16651: CWE-129: Improper Validation of Array Index in Temporal Technologies, Inc. temporalio/sqlparser
Description
CVE-2026-16651 is a high-severity vulnerability in Temporal Technologies, Inc.'s temporalio/sqlparser. The parser can panic when processing a MySQL version comment that is empty or contains only one to five decimal digits due to improper validation of array indices. This leads to a Go runtime panic that can terminate the parsing goroutine. Temporal Server exposes this parser through the ListWorkers API, allowing an authenticated user with namespace read permission to submit malformed queries that cause the Matching process to terminate. Repeated exploitation can cause a denial of service. The vulnerability affects availability only, with no impact on confidentiality or integrity.
CVSS v4.0
Score 8.7high
Affected software
Temporal Technologies, Inc.
temporalio/sqlparser
Temporal Technologies, Inc.
Temporal Server
pkg:golang/github.com/temporalio/sqlparserpkg:golang/go.temporal.io/servercpe:2.3:a:temporal:temporal:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The temporalio/sqlparser component improperly validates array indices when parsing MySQL version comments. Specifically, the ExtractMysqlComment function uses the result of strings.IndexFunc without checking for a -1 return value, leading to out-of-bounds slice operations and a runtime panic in Go. This panic propagates unless recovered by the caller. Temporal Server exposes this parser via the ListWorkers API, which when enabled, allows authenticated users with namespace read permission to send malformed SQL queries that cause the Matching process to crash. This can be exploited repeatedly to sustain a denial of service condition. No confidentiality or integrity impacts are reported.
Potential Impact
The vulnerability causes denial of service by crashing the Matching process in Temporal Server when parsing malformed SQL queries. It affects availability only. There is no known impact on confidentiality or integrity. Exploitation requires authentication with namespace read permission and the ListWorkers API to be enabled.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the ListWorkers API to trusted users only and monitor for abnormal termination of the Matching process. Applications should implement recovery mechanisms for panics in parsing goroutines if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Temporal
- Date Reserved
- 2026-07-22T18:08:54.825Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab1194455bf5e2cf5d2cb4b
Added to database: 09/21/2026, 11:47:16 UTC
Last enriched: 09/21/2026, 12:02:15 UTC
Last updated: 09/21/2026, 14:29:35 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.