Impact
Hatchet through version 0.110.5 has an unbounded memory allocation issue that lets attackers send arbitrary large or concurrent request bodies to the SNS ingestion endpoint. The handler buffers the payload before it is signed, meaning an attacker can exhaust server memory without using any form of authentication. As a result, the application can become unavailable, leading to a denial of service. This flaw aligns with CWE‑770 resource exhaustion.
Affected Systems
The affected product is Hatchet from hatchet‑dev, specifically versions up to and including 0.110.5. The vulnerability is triggered by the POST /api/v1/sns/{tenant}/{event} endpoint, which is exposed without authentication.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, while no EPSS score is currently available. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it remotely through the public SNS ingestion endpoint without authentication. By sending large payloads or a high volume of concurrent requests, an attacker can trigger a memory exhaustion that degrades availability. Because the attack does not require privileged credentials, it poses a substantial risk to deployments exposing the endpoint.
OpenCVE Enrichment