StackRadar

CVE-2025-14986

Medium

Advisory

Published 30 Dec 2025In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts

Carried by container images the latest versions of 4 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
go.temporal.io/servergolangv1.24.2, v1.26.2-125.1, v1.29.01.27.4, 1.29.27
OSV records
GHSA-p2gr-hm8g-q772
Also known as
GO-2025-4272

Charts affected

4 by stars
ChartLatestAffected imagesRadar Score
agentareaagentareaVerified publisher0.0.181 of 16See more

agentarea agentarea 0.0.18

1 of the 16 container images this version deploys carry CVE-2025-14986.

Container imageDigestPackageFixed in
temporalio/auto-setup:1.29.15b3502a3b685
go.temporal.io/server@v1.29.0
1.29.2

Open the chart page →

14,914
temporalglasskubeVerified publisher0.45.2-gk.12 of 14See more

temporal glasskube 0.45.2-gk.1

2 of the 14 container images this version deploys carry CVE-2025-14986.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
go.temporal.io/server@v1.24.2
1.27.4
temporalio/server:1.25.08a5798191dea
go.temporal.io/server@v1.24.2
1.27.4

Open the chart page →

16,346
temporalcastaiVerified publisher0.54.22 of 14See more

temporal castai 0.54.2

2 of the 14 container images this version deploys carry CVE-2025-14986.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.26.237e2e33dbd7b
go.temporal.io/server@v1.26.2-125.1
1.27.4
temporalio/server:1.26.21e2626efcbc1
go.temporal.io/server@v1.26.2-125.1
1.27.4

Open the chart page →

16,198
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2025-14986.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
go.temporal.io/server@v1.29.0
1.29.2
temporalio/server:1.29.1c1e3326b2ce1
go.temporal.io/server@v1.29.0
1.29.2

Open the chart page →

14,983

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
temporalio/admin-tools:1.26.237e2e33dbd7b
go.temporal.io/server@v1.26.2-125.1
1.27.4
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
go.temporal.io/server@v1.29.0
1.29.2
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
go.temporal.io/server@v1.24.2
1.27.4
1
temporalio/auto-setup:1.29.15b3502a3b685
go.temporal.io/server@v1.29.0
1.29.2
1
temporalio/server:1.26.21e2626efcbc1
go.temporal.io/server@v1.26.2-125.1
1.27.4
1
temporalio/server:1.25.08a5798191dea
go.temporal.io/server@v1.24.2
1.27.4
1
temporalio/server:1.29.1c1e3326b2ce1
go.temporal.io/server@v1.29.0
1.29.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.