Reliance on Untrusted Inputs in a Security Decision Affecting github.com/temporalio/temporal/components/callbacks package, versions >=1.30.0 <1.30.7>=1.31.0 <1.31.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.78% (54th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMTEMPORALIOTEMPORALCOMPONENTSCALLBACKS-20074846
  • published24 Sept 2026
  • disclosed21 Sept 2026

Introduced: 21 Sep 2026

NewCVE-2026-87858  (opens in a new tab)
CWE-807  (opens in a new tab)

How to fix?

Upgrade github.com/temporalio/temporal/components/callbacks to version 1.30.7, 1.31.3 or higher.

Overview

Affected versions of this package are vulnerable to Reliance on Untrusted Inputs in a Security Decision through the Nexus callback routing logic in chasm/lib/callback/request.go and components/callbacks/request.go. An attacker can make the History service send a state-changing internal HTTP request as an administrator by supplying a callback URL that matches the allowed callback host and setting a non-empty source header on the callback request. The vulnerable routing path treats that caller-controlled header as proof that the callback is internal and rewrites the request to the local frontend client while preserving the attacker-chosen path, query, and body. In deployments with an internal frontend HTTP API enabled, this lets an authenticated namespace user trigger administrative actions such as terminating workflows, registering namespaces, changing namespace configuration, or deleting namespaces and their workflows in namespaces they do not control.

CVSS Base Scores

version 4.0
version 3.1