PT-2026-96141 · Hatchet · Hatchet
CVE-2026-61681
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
4.1
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hatchet versions prior to 0.91.1
Description
The SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go performs an http.Get() request on the
UnsubscribeURL parameter within the payload. Because the BuildSignature() function excludes UnsubscribeURL, an authenticated tenant can modify this field in a valid AWS-signed message to point to an internal URL. This allows for server-side requests to reach the EC2 Instance Metadata Service, internal services, and internal HTTP APIs, which could lead to the exposure of IAM credentials or internal network data and functionality.Recommendations
Update to version 0.91.1.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hatchet