๐Ÿ” CVE Alert

CVE-2026-65655

UNKNOWN 0.0

Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-server connection. Temporal UI Server can therefore issue access-token cookies, and refresh-token cookies when provided by the identity provider, without Secure even though the browser completed login over HTTPS. A victim who visits attacker-controlled content while a credential remains live may expose that credential only if the attacker can also steer traffic for the UI hostname, prevent the browser's HTTPS connection from succeeding, serve the hostname over HTTP, and read a later same-site plaintext request. A malicious website alone cannot read the cookie, and passive observation of a successful TLS connection is insufficient. Effective HSTS, a blocking HTTPS-only warning, or TLS re-encryption between the proxy and Temporal UI Server prevents the demonstrated disclosure path. A recovered credential may be replayed within the victim's assigned permissions. Refresh-token replay additionally depends on the identity provider's issuance, expiry, rotation, and reuse-detection behavior.

CWE CWE-614
Vendor temporal technologies, inc.
Product temporal ui server
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for temporal technologies, inc. temporal ui server

Be the first to know when new unknown vulnerabilities affecting temporal technologies, inc. temporal ui server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Temporal Technologies, Inc. / Temporal UI Server
2.7.0 < 2.53.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/temporalio/ui-server/commit/821cf598371353f1b579dfe1e87aeb3638b041d6 github.com: https://github.com/temporalio/ui-server/commit/7b9ff533fb51beba75497c0a192c66775c08f279 github.com: https://github.com/temporalio/ui-server/blob/v2.53.1/server/auth/auth.go#L87-L153 github.com: https://github.com/temporalio/ui-server/blob/v2.53.1/server/route/auth.go#L281-L316 github.com: https://github.com/temporalio/ui-server/releases/tag/v2.53.1 github.com: https://github.com/temporalio/ui/pull/3806 github.com: https://github.com/temporalio/ui-server/commit/8876b80b63003688ab736f45ef28885695a4f6db github.com: https://github.com/temporalio/ui-server/releases/tag/v2.53.2

Credits

An external security researcher who reported this issue responsibly to Temporal Technologies