Summary
CVE-2026-93450 (high, 7.5) in github.com/go-openapi/swag v0.26.0, compiled into temporal-server in temporalio/server:1.32.0
Advisory
Unbounded recursion in swag's ordered JSON marshal/unmarshal (jsonutils/adapters/stdlib/json) lets a deeply nested JSON document cause a fatal stack overflow. Fixed in v0.27.1 (latest: v0.29.2).
Summary
CVE-2026-93450 (high, 7.5) in
github.com/go-openapi/swagv0.26.0, compiled intotemporal-serverintemporalio/server:1.32.0Advisory
Unbounded recursion in swag's ordered JSON marshal/unmarshal (
jsonutils/adapters/stdlib/json) lets a deeply nested JSON document cause a fatal stack overflow. Fixed in v0.27.1 (latest: v0.29.2).