CVE-2026-16652: Temporal Server Schedule exclusion search can cause excessive CPU consumption

Published Sep 21, 2026
·
Updated

Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create or update a Schedule that combines a fine-grained cadence with an exclusion calendar that rejects every candidate time, causing the server to evaluate excluded candidates without a per-search work budget. This can consume excessive CPU in Frontend and Schedule worker components. A persisted specification can also cause its backing Schedule Workflow to repeatedly fail and retry, allowing CPU consumption to continue without additional requests until the Schedule is deleted or its backing Workflow is terminated. Repeated or parallel exploitation can deny service. The issue affects availability only; it does not expose or modify Workflow data.

Affected Software

1 affected component
Temporal Server

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Temporal Server to a version that resolves this vulnerability.

    Fixed in 1.30.7
  2. Upgrade

    Upgrade Temporal Server to a version that resolves this vulnerability.

    Fixed in 1.31.3
  3. Upgrade

    Upgrade Temporal Server to a version that resolves this vulnerability.

    Fixed in 1.32.0
  4. Configuration

    Set scheduler.specMaxIterations to a positive (non-zero, non-negative) value; setting it to zero or a negative value disables the hard bound.

    Temporal Server scheduler.specMaxIterations = positive
  5. Compensating control

    Review and replace or remove Schedule specifications that exceed the configured bound to prevent excessive CPU consumption from Schedule exclusion searches and repeated failure/retry behavior.

Event History

Sep 21, 2026
CVE Published
via MITRE·11:23 AM
Data Sourced
via MITRE·11:23 AM
RemedyDescriptionWeakness

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203