# Tchannel-go security issue related to older Tally/Thrift

**URL:** <https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378>\
**Category:** Community Support\
**Tags:** security\
**Created:** [February 23, 2023, 7:36pm UTC](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378 "2023-02-23T19:36:53Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![tareque](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tareque/32/961_2.png) [@tareque](https://community.temporal.io/u/tareque)\
**Post date:** [February 23, 2023, 7:36pm UTC](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378/1 "2023-02-23T19:36:53Z")

</div>

Hi folks, [GitHub - temporalio/tchannel-go: Go implementation of a multiplexing and framing protocol for RPC calls](https://github.com/temporalio/tchannel-go) is importing a fairly old [GitHub - uber-go/tally: A Go metrics interface with fast buffered metrics and third party reporters](http://github.com/uber-go/tally) v3.3.15 that [uses Thrift 0.10.0](https://github.com/uber-go/tally/tree/v3.3.15/thirdparty/github.com/apache/thrift/lib/go/thrift)

This results in several CVEs.

High vulnerability:  
CVE-2019-0205  
CVE-2019-0205  
CVE-2018-11798  
CVE-2015-3254

Medium vulnerability:  
CVE-2020-13949  
CVE-2019-0210

I see that the most [recent commit](https://github.com/temporalio/tchannel-go/blob/dev/go.mod#L6) in tchannel-go explicitly upgrades Thrift to 0.16.0 but 0.10.0 is also included due to the older Tally.

Would it be possible to explore upgrading Tally version in tchannel-go? Thanks.

---

<div class="post-metadata">

**Author:** ![tihomir](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tihomir/32/6580_2.png) [@tihomir](https://community.temporal.io/u/tihomir)\
**Post date:** [February 25, 2023, 6:25am UTC](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378/3 "2023-02-25T06:25:06Z")

</div>

Hi, thanks a lot for sharing this info. Will get more info from our security team and get back to you asap.

---

<div class="post-metadata">

**Author:** ![tareque](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tareque/32/961_2.png) [@tareque](https://community.temporal.io/u/tareque)\
**Post date:** [February 27, 2023, 8:42pm UTC](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378/4 "2023-02-27T20:42:45Z")

</div>

Thank you @tihomir. Please let me know.

---

<div class="post-metadata">

**Author:** ![tihomir](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tihomir/32/6580_2.png) [@tihomir](https://community.temporal.io/u/tihomir)\
**Post date:** [February 27, 2023, 8:52pm UTC](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378/5 "2023-02-27T20:52:59Z")

</div>

Will do, as soon as I get some info will update here.

---

<div class="post-metadata">

**Author:** ![tihomir](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tihomir/32/6580_2.png) [@tihomir](https://community.temporal.io/u/tihomir)\
**Post date:** [February 27, 2023, 9:00pm UTC](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378/6 "2023-02-27T21:00:53Z")

</div>

Just to add, we have issue [here](https://github.com/temporalio/temporal/issues/3370) that is related as well as issue opened with tally [here](https://github.com/uber-go/tally/issues/182).

---

<div class="post-metadata">

**Author:** ![tareque](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tareque/32/961_2.png) [@tareque](https://community.temporal.io/u/tareque)\
**Post date:** [February 27, 2023, 10:35pm UTC](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378/7 "2023-02-27T22:35:46Z")

</div>

Makes sense. It does seem like tally will have to remove that fixed vendoring. They have moved towards Go module so I don’t see why it is still vendored.

---

<div class="post-metadata">

**Author:** ![tihomir](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tihomir/32/6580_2.png) [@tihomir](https://community.temporal.io/u/tihomir)\
**Post date:** [February 27, 2023, 10:38pm UTC](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378/8 "2023-02-27T22:38:25Z")

</div>

Eng team mentioned that Temporal does have dependency for ringpop, but we do not use the Thrift protocol in any way. We also have plan to deprecate ringpop in the future.

---

<div class="post-metadata">

**Author:** ![tareque](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tareque/32/961_2.png) [@tareque](https://community.temporal.io/u/tareque)\
**Post date:** [February 28, 2023, 10:43pm UTC](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378/9 "2023-02-28T22:43:42Z")

</div>

Understood. Thanks for the responses @tihomir 🙌
