CyberRota Analysis
AI-GeneratedThe vulnerability affects the temporalio/sqlparser, which can experience a runtime panic when processing certain malformed MySQL version comments, specifically those that are empty or consist solely of one to five decimal digits. This flaw can lead to denial of service for applications that parse SQL queries, particularly impacting the Temporal Server's ListWorkers API, where an authenticated user can exploit this to terminate the Matching process. Organizations utilizing Temporal Server should prioritize addressing this issue to prevent potential service disruptions from attacker-controlled SQL queries.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by strings.IndexFunc before using it as a slice boundary. The resulting Go runtime panic propagates unless the caller recovers it on the parsing goroutine, so applications that parse attacker-controlled SQL can terminate. Temporal Server exposes the affected parser through ListWorkers. When that API is enabled, an authenticated caller with namespace read permission can submit a malformed query that terminates the receiving Matching process. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.