CVE-2026-87858

CVE-2026-87858 published: Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose URL host matched the c...

View full NVD advisory → ← Back to CVE watch