๐Ÿ” CVE Alert

CVE-2026-61681

MEDIUM 4.1

Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler

CVSS Score
4.1
EPSS Score
0.0%
EPSS Percentile
0th

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go calls http.Get() on payload.UnsubscribeURL after VerifyPayload() even though BuildSignature() excludes UnsubscribeURL, allowing an authenticated Hatchet tenant to replace that field in an otherwise valid AWS-signed message with an internal URL. The server-side request can reach EC2 Instance Metadata Service, internal services, and internal HTTP APIs, potentially exposing IAM credentials or network-accessible data and functionality. This issue is fixed in version 0.91.1.

CWE CWE-918
Vendor hatchet-dev
Product hatchet
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for hatchet-dev hatchet

Be the first to know when new medium vulnerabilities affecting hatchet-dev hatchet are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

hatchet-dev / hatchet
< 0.91.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-fjwv-jf2v-j499 github.com: https://github.com/hatchet-dev/hatchet/commit/2d211bce16e5022afaf95780de82dc30e0bcba98