Temporal Technologies, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with Temporal UI Server.
Products
Clear product- temporal2 vulnerabilities
- api-go library1 vulnerability
- Temporal Server1 vulnerability
- Temporal UI Server1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxyWhen OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-server connection. Temporal UI Server can therefore issue access-token cookies, and refresh-token cookies when provided by the identity provider, without Secure even though the browser completed login over HTTPS. A victim who visits attacker-controlled content whi… CWE-614Aug 11, 2026 | CVSS2.3v4.0 | EPSS0.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |