Server-Side Request Forgery Vulnerability in Hatchet Platform
CVE-2026-61681
4.1MEDIUM
What is CVE-2026-61681?
The Hatchet platform, used for orchestrating background tasks and workflows, contains a server-side request forgery vulnerability. Specifically, prior to version 0.91.1, the SNS UnsubscribeConfirmation handler improperly processes the unsubscribe URL in valid AWS-signed messages. This allows authenticated tenants to manipulate the URL, redirecting server-side requests to internal services and EC2 Instance Metadata Service. Such actions could lead to unauthorized exposure of IAM credentials and sensitive data within the network, highlighting the importance of updating to the patched version to mitigate these risks.
Affected Version(s)
hatchet < 0.91.1
