Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fjwv-jf2v-j499 | Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 24 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hatchet-dev
Hatchet-dev hatchet |
|
| Vendors & Products |
Hatchet-dev
Hatchet-dev hatchet |
Mon, 21 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go calls http.Get() on payload.UnsubscribeURL after VerifyPayload() even though BuildSignature() excludes UnsubscribeURL, allowing an authenticated Hatchet tenant to replace that field in an otherwise valid AWS-signed message with an internal URL. The server-side request can reach EC2 Instance Metadata Service, internal services, and internal HTTP APIs, potentially exposing IAM credentials or network-accessible data and functionality. This issue is fixed in version 0.91.1. | |
| Title | Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-24T22:17:06.909Z
Reserved: 2026-07-10T18:36:58.848Z
Link: CVE-2026-61681
Updated: 2026-09-24T22:17:02.329Z
Status : Deferred
Published: 2026-09-21T16:17:09.823
Modified: 2026-09-24T23:17:13.400
Link: CVE-2026-61681
No data.
OpenCVE Enrichment
Updated: 2026-09-21T17:30:18Z
Github GHSA