<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T05:25:20.342026+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-iz19721</id>
    <title>Withdrawn: CLEANSTART-2026-IZ19721 — Security fixes in temporal-server 1.31.1-r5</title>
    <updated>2026-10-10T05:25:20.363081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: temporal-server</p>
<p>Package temporal-server version 1.31.1-r5 fixes 9 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-5724, ghsa-q98v-9f9w-f49q, ghsa-hmhp-gh8m-c8xp, ghsa-p2gr-hm8g-q772...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-iz19721"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-14986</id>
    <title>CVE-2025-14986 — ExecuteMultiOperation Namespace Policy Bypass</title>
    <updated>2026-10-10T05:25:20.363141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Temporal</p>
<p>When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows a caller authorized for one namespace to bypass that namespace's limits/policies by setting the embedded start request's namespace to a different namespace. The workflow is still created in the outer (authorized) namespace; only validation/gating is performed under the wrong namespace context.
This issue affects Temporal: from 1.24.0 through 1.29.1. Fixed in 1.27.4, 1.28.2, 1.29.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-14986"/>
  </entry>
</feed>
