PT-2026-96141 · Hatchet · Hatchet

CVE-2026-61681

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hatchet versions prior to 0.91.1
Description The SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go performs an http.Get() request on the UnsubscribeURL parameter within the payload. Because the BuildSignature() function excludes UnsubscribeURL, an authenticated tenant can modify this field in a valid AWS-signed message to point to an internal URL. This allows for server-side requests to reach the EC2 Instance Metadata Service, internal services, and internal HTTP APIs, which could lead to the exposure of IAM credentials or internal network data and functionality.
Recommendations Update to version 0.91.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61681
GHSA-FJWV-JF2V-J499

Affected Products

Hatchet