CyberRota Analysis
AI-GeneratedThe vulnerability arises in the temporalio/sqlparser library, which fails to enforce a nesting limit on deeply nested unary expressions, leading to potential stack overflow during the parsing of attacker-controlled SQL. This can result in a denial of service by terminating the Temporal Server's Frontend or Matching processes, particularly affecting authenticated deployments where users have namespace read permissions. Organizations utilizing Temporal Server should prioritize addressing this issue to mitigate availability risks associated with malicious SQL queries.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later formats or walks the returned tree can encounter a runtime-fatal Go stack overflow that terminates the process; Go panic recovery cannot contain this condition. Temporal Server passes caller-controlled query input through the affected parser in archival, visibility, and worker-query paths. In affected validation paths, the Server recursively formats an invalid expression while constructing an error. In a supported authenticated deployment, a caller with namespace read permission can terminate the receiving Frontend or Matching process. The dynamically confirmed ListWorkers route additionally requires at least one retained worker heartbeat. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.