PT-2026-96144 · Hatchet · Hatchet

CVE-2026-84298

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hatchet versions prior to 0.95.3
Description The V1 DurableTask stream handler stores worker-supplied task external id values in the durableInvocations routing map before verifying tenant ownership. Because callback delivery resolves this map using the task UUID without checking tenant identity, an authenticated tenant worker could receive the durable callback result payload of another tenant if they know the target task UUID and maintain an open stream on the same dispatcher process. This issue does not affect single-tenant deployments, and UUIDv4 values are not enumerable.
Recommendations Update to version 0.95.3.

Exploit

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84298
GHSA-9Q4H-F4X5-FFQ8

Affected Products

Hatchet