Description
Hatchet through 0.110.5 contains an allocation of resources without limits vulnerability that allows unauthenticated attackers to exhaust memory via the SNS ingestion endpoint. Attackers can send arbitrarily large or concurrent request bodies to POST /api/v1/sns/{tenant}/{event} with any UUID, which the SnsUpdate handler buffers before signature verification, degrading availability.
Published: 2026-10-11
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated Memory Exhaustion
Action: Apply Patch
AI Analysis

Impact

Hatchet through version 0.110.5 has an unbounded memory allocation issue that lets attackers send arbitrary large or concurrent request bodies to the SNS ingestion endpoint. The handler buffers the payload before it is signed, meaning an attacker can exhaust server memory without using any form of authentication. As a result, the application can become unavailable, leading to a denial of service. This flaw aligns with CWE‑770 resource exhaustion.

Affected Systems

The affected product is Hatchet from hatchet‑dev, specifically versions up to and including 0.110.5. The vulnerability is triggered by the POST /api/v1/sns/{tenant}/{event} endpoint, which is exposed without authentication.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, while no EPSS score is currently available. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it remotely through the public SNS ingestion endpoint without authentication. By sending large payloads or a high volume of concurrent requests, an attacker can trigger a memory exhaustion that degrades availability. Because the attack does not require privileged credentials, it poses a substantial risk to deployments exposing the endpoint.

Generated by OpenCVE AI on October 11, 2026 at 13:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Hatchet release that contains a fix for the unbounded memory allocation in the SNS ingestion endpoint.
  • Configure rate limiting on the /api/v1/sns endpoint to cap the number of concurrent requests and limit payload size per request.
  • Deploy a reverse proxy or API gateway that enforces a maximum request body size before traffic reaches the Hatchet service, preventing large bodies from exhausting server memory.

Generated by OpenCVE AI on October 11, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Hatchet through 0.110.5 contains an allocation of resources without limits vulnerability that allows unauthenticated attackers to exhaust memory via the SNS ingestion endpoint. Attackers can send arbitrarily large or concurrent request bodies to POST /api/v1/sns/{tenant}/{event} with any UUID, which the SnsUpdate handler buffers before signature verification, degrading availability.
Title Hatchet through 0.110.5 Unauthenticated Memory Exhaustion via SNS Ingestion Endpoint
First Time appeared Hatchet
Hatchet hatchet
Weaknesses CWE-770
CPEs cpe:2.3:a:hatchet:hatchet:*:*:*:*:*:*:*:*
Vendors & Products Hatchet
Hatchet hatchet
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:53.976Z

Reserved: 2026-10-11T01:54:18.584Z

Link: CVE-2026-108755

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T13:17:20.517

Modified: 2026-10-11T13:17:20.633

Link: CVE-2026-108755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:00:18Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling