CVE-2026-108755
Hatchet through 0.110.5 Unauthenticated Memory Exhaustion via SNS Ingestion Endpoint
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
Hatchet through 0.110.5 contains an allocation of resources without limits vulnerability that allows unauthenticated attackers to exhaust memory via the SNS ingestion endpoint. Attackers can send arbitrarily large or concurrent request bodies to POST /api/v1/sns/{tenant}/{event} with any UUID, which the SnsUpdate handler buffers before signature verification, degrading availability.
| CWE | CWE-770 |
| Vendor | hatchet-dev |
| Product | hatchet |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for hatchet-dev hatchet
Be the first to know when new medium vulnerabilities affecting hatchet-dev hatchet are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected Versions
hatchet-dev / hatchet
0 โค 0.110.5
References
hackmd.io: https://hackmd.io/@haind03/hatchet-public-sns-unbounded-body-before-signature-dos github.com: https://github.com/hatchet-dev/hatchet/blob/56c617e0da399bc9d8a10d2ba74b4950f8a950b8/api/v1/server/handlers/ingestors/sns.go#L15-L32 github.com: https://github.com/hatchet-dev/hatchet/blob/56c617e0da399bc9d8a10d2ba74b4950f8a950b8/api/v1/server/middleware/ratelimit/ratelimit.go#L33-L49 github.com: https://github.com/hatchet-dev/hatchet vulncheck.com: https://www.vulncheck.com/advisories/hatchet-through-0.110.5-unauthenticated-memory-exhaustion-via-sns-ingestion-endpoint
Credits
HaiND from the Post and Telecommunication Institute of Technology