๐Ÿ” CVE Alert

CVE-2026-84298

LOW 3.1

Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map before tenant ownership is verified, and callback delivery resolves that map by task UUID without tenant identity. An authenticated tenant worker that knows another tenant's durable task UUID and keeps a stream open on the same dispatcher process can receive that task's durable callback result payload. UUIDv4 values are not enumerable, and single-tenant deployments are unaffected in practice. This issue is fixed in version 0.95.3.

CWE CWE-639 CWE-862
Vendor hatchet-dev
Product hatchet
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for hatchet-dev hatchet

Be the first to know when new low vulnerabilities affecting hatchet-dev hatchet are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

hatchet-dev / hatchet
< 0.95.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-9q4h-f4x5-ffq8 github.com: https://github.com/hatchet-dev/hatchet/commit/9555bfdd1e97f61d25e614ccaa107c5fb7dc4976