Server-Side Request Forgery Vulnerability in Hatchet Platform
CVE-2026-61681

4.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-61681?

The Hatchet platform, used for orchestrating background tasks and workflows, contains a server-side request forgery vulnerability. Specifically, prior to version 0.91.1, the SNS UnsubscribeConfirmation handler improperly processes the unsubscribe URL in valid AWS-signed messages. This allows authenticated tenants to manipulate the URL, redirecting server-side requests to internal services and EC2 Instance Metadata Service. Such actions could lead to unauthorized exposure of IAM credentials and sensitive data within the network, highlighting the importance of updating to the patched version to mitigate these risks.

Affected Version(s)

hatchet < 0.91.1

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.