Junglewise Threat Intelligence

CVE-2026-65651: temporalio sqlparser stack overflow in deeply nested unary expressions

CVE-2026-65651 · Severity: info · Published 2026-09-21

Executive brief

temporalio/sqlparser is a SQL query parser library used by Temporal Server to process database queries in its archival, visibility, and worker-query paths. An attacker who can submit SQL queries with deeply nested unary expressions can trigger a fatal stack overflow that crashes the process. In Temporal Server deployments, authenticated users with namespace read permission can exploit this to repeatedly crash critical components like Frontend or Matching processes, causing denial of service.

Technical details

The vulnerability exists because sqlparser does not enforce a nesting depth limit on unary expressions, allowing arbitrarily deep abstract syntax trees to be constructed. The library's String and Walk operations recursively traverse this tree without protection, causing a fatal Go stack overflow when the recursion depth exceeds available stack space; Go's panic recovery mechanism cannot contain this condition. Temporal Server amplifies the risk by parsing caller-controlled SQL in multiple code paths and recursively formatting invalid expressions during error construction, enabling authenticated remote attackers to terminate the process.

Affected products

  • temporalio sqlparser
  • temporalio Temporal Server

Timeline

  • 2026-09-21: disclosed

References