๐Ÿ” CVE Alert

CVE-2026-108755

MEDIUM 5.3

Hatchet through 0.110.5 Unauthenticated Memory Exhaustion via SNS Ingestion Endpoint

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Hatchet through 0.110.5 contains an allocation of resources without limits vulnerability that allows unauthenticated attackers to exhaust memory via the SNS ingestion endpoint. Attackers can send arbitrarily large or concurrent request bodies to POST /api/v1/sns/{tenant}/{event} with any UUID, which the SnsUpdate handler buffers before signature verification, degrading availability.

CWE CWE-770
Vendor hatchet-dev
Product hatchet
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for hatchet-dev hatchet

Be the first to know when new medium vulnerabilities affecting hatchet-dev hatchet are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

hatchet-dev / hatchet
0 โ‰ค 0.110.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind03/hatchet-public-sns-unbounded-body-before-signature-dos github.com: https://github.com/hatchet-dev/hatchet/blob/56c617e0da399bc9d8a10d2ba74b4950f8a950b8/api/v1/server/handlers/ingestors/sns.go#L15-L32 github.com: https://github.com/hatchet-dev/hatchet/blob/56c617e0da399bc9d8a10d2ba74b4950f8a950b8/api/v1/server/middleware/ratelimit/ratelimit.go#L33-L49 github.com: https://github.com/hatchet-dev/hatchet vulncheck.com: https://www.vulncheck.com/advisories/hatchet-through-0.110.5-unauthenticated-memory-exhaustion-via-sns-ingestion-endpoint

Credits

HaiND from the Post and Telecommunication Institute of Technology