CVE-2026-16651
temporalio/sqlparser malformed MySQL version comments can cause a panic
temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by strings.IndexFunc before using it as a slice boundary. The resulting Go runtime panic propagates unless the caller recovers it on the parsing goroutine, so applications that parse attacker-controlled SQL can terminate. Temporal Server exposes the affected parser through ListWorkers. When that API is enabled, an authenticated caller with namespace read permission can submit a malformed query that terminates the receiving Matching process. Repeated requests can sustain a denial of service. The issue affects availability only; no confidentiality or integrity impact was identified.
| CWE | CWE-129 |
| Vendor | temporal technologies, inc. |
| Product | temporalio/sqlparser |
| Published | Sep 21, 2026 |
Get instant alerts for temporal technologies, inc. temporalio/sqlparser
Be the first to know when new unknown vulnerabilities affecting temporal technologies, inc. temporalio/sqlparser are published โ delivered to Slack, Telegram or Discord.