CVE-2024-2689: Denial of Service if invalid UTF-8 sent

Published Apr 3, 2024
·
Updated

Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an invalid UTF-8 string for submission to potentially cause a crashloop. If left unchecked, the task containing the invalid UTF-8 will become stuck in the queue, causing an increase in queue lag. Eventually, all processes handling these queues will become stuck and the system will run out of resources. The workflow ID of the failing task will be visible in the logs, and can be used to remove that workflow as a mitigation. Version 1.23 is not impacted. In this context, a user is an operator of Temporal Server.

Affected Software

4 affected componentsFixes available
go/github.com/temporalio/temporal<1.20.5
1.20.5
go/github.com/temporalio/temporal>=1.21.0<1.21.6
1.21.6
go/github.com/temporalio/temporal>=1.22.0-rc1<1.22.7
1.22.7
IBM Concert Software<=1.0.0-2.1.0

Event History

Apr 3, 2024
CVE Published
via MITRE·09:13 PM
Data Sourced
via MITRE·09:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Apr 4, 2024
Advisory Published
via GitHub·12:33 AM
Jan 21, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-2689?

CVE-2024-2689 is classified as a Denial of Service vulnerability that can cause crashes in Temporal Server.

2

How do I fix CVE-2024-2689?

To resolve CVE-2024-2689, upgrade to Temporal Server versions 1.20.5, 1.21.6, or 1.22.7 or later.

3

What software is affected by CVE-2024-2689?

CVE-2024-2689 affects Temporal Server versions prior to 1.20.5, 1.21.6, and 1.22.7.

4

Who can trigger the vulnerability in CVE-2024-2689?

Authenticated users with permissions to interact with workflows can trigger CVE-2024-2689 by submitting crafted invalid UTF-8 strings.

5

What happens if CVE-2024-2689 is exploited?

Exploiting CVE-2024-2689 may cause a crashloop in the Temporal Server, affecting its availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203