Executive brief
Temporal's tchannel-go library, which handles inter-service network communication, crashes when receiving malformed message fragments from untrusted peers. An attacker on the network can send crafted TChannel call fragments that cause the host process to terminate, disrupting service availability. No data theft or corruption is possible, only availability impact.
Technical details
The fragment reader in tchannel-go fails to validate that TChannel call fragments with checksum metadata contain at least one length-prefixed argument chunk. When such malformed fragments are received, the code attempts to access the first element of an empty chunk slice, triggering an unrecovered panic in a dispatch goroutine. This occurs on the inbound path after the TChannel handshake, allowing any network-accessible peer to trigger remote process termination.
Affected products
- Temporal tchannel-go before fix
Timeline
- 2026-09-21: disclosed