Junglewise Threat Intelligence

CVE-2026-65655: Temporal UI Server insecure OAuth cookie in reverse proxy setup

CVE-2026-65655 · Severity: info · Published 2026-08-11

Vendors: Temporal Technologies.

Executive brief

Temporal UI Server is a web interface for managing Temporal workflow orchestration. When OAuth login is enabled behind a reverse proxy that terminates TLS on the browser side but forwards to the server over unencrypted HTTP, authentication cookies are issued without the Secure flag, allowing them to be transmitted over plaintext connections. An attacker who controls the victim's network or DNS could steal these credentials and replay them within the victim's permissions.

Technical details

The vulnerability is an insecure cookie configuration (missing Secure flag) in OAuth authentication flow. The root cause is that Temporal UI Server derives the cookie's Secure attribute from the proxy-to-server connection rather than the browser-facing connection. When TLS terminates at a reverse proxy and the proxy forwards the OAuth callback over HTTP to the server, the server incorrectly issues access-token and refresh-token cookies without the Secure flag, despite the browser completing login over HTTPS. Exploitation requires the attacker to intercept the connection between browser and proxy, prevent HTTPS success, and serve the hostname over HTTP to capture the cookie in plaintext. HSTS, HTTPS-only warnings, or re-encryption between proxy and server can prevent this attack.

Affected products

  • Temporal Technologies UI Server before a fix version (version details not specified in advisory)

Timeline

  • 2026-08-11: disclosed

References