Description
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map before tenant ownership is verified, and callback delivery resolves that map by task UUID without tenant identity. An authenticated tenant worker that knows another tenant's durable task UUID and keeps a stream open on the same dispatcher process can receive that task's durable callback result payload. UUIDv4 values are not enumerable, and single-tenant deployments are unaffected in practice. This issue is fixed in version 0.95.3.
Published: 2026-09-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Cross-tenant data disclosure
Action: Patch
AI Analysis

Impact

Hatchet, a platform for orchestrating background tasks and durable workflows, has a flaw where a V1 Dispatcher operation stores a worker’s supplied task_external_id in a routing map before verifying tenant ownership, and later resolves callback delivery by task UUID without tenant context. This allows an authenticated worker from one tenant to open a stream on the same dispatcher process and receive the durable callback result payload of a task belonging to another tenant. The vulnerability leads to the exposure of potentially sensitive data across tenant boundaries, compromising confidentiality. The weakness is classified by CWE-639 (Information Exposure Through Incomplete Authentication) and CWE-862 (Missing Authorization).

Affected Systems

The Hatchet platform, specifically the hatchet-dev Hatchet product, is affected in all releases prior to version 0.95.3. Users of earlier releases that rely on the V1 Dispatcher for durable tasks may be susceptible to this cross‑tenant disclosure. Single‑tenant deployments are not practically impacted because the issue requires multiple tenants sharing the same dispatcher.

Risk and Exploitability

The CVSS score for this vulnerability is 3.1, reflecting a low severity primarily due to its limited exploitation scope and the need for an authenticated worker with a shared dispatcher process. EPSS information is not available, so a precise exploitation probability cannot be quoted. The vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The likely attack vector requires an attacker to authenticate as a legitimate worker, identify another tenant’s durable task UUID, and maintain an open stream on the shared dispatcher. Given these prerequisites, the risk, while real, is constrained to environments where multiple tenants share dispatcher resources.

Generated by OpenCVE AI on September 21, 2026 at 17:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hatchet to version 0.95.3 or later, which corrects the tenant verification logic before storing task_external_id.
  • If an upgrade cannot be performed immediately, isolate tenant workloads so that each tenant uses a separate dispatcher instance, preventing cross‑tenant stream access.
  • Implement network or process isolation between tenants to ensure that a worker cannot open streams on a dispatcher used by another tenant, thereby limiting the potential for callback payload exposure.

Generated by OpenCVE AI on September 21, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9q4h-f4x5-ffq8 Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Hatchet-dev
Hatchet-dev hatchet
Vendors & Products Hatchet-dev
Hatchet-dev hatchet

Mon, 21 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map before tenant ownership is verified, and callback delivery resolves that map by task UUID without tenant identity. An authenticated tenant worker that knows another tenant's durable task UUID and keeps a stream open on the same dispatcher process can receive that task's durable callback result payload. UUIDv4 values are not enumerable, and single-tenant deployments are unaffected in practice. This issue is fixed in version 0.95.3.
Title Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
Weaknesses CWE-639
CWE-862
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hatchet-dev Hatchet
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T18:49:20.918Z

Reserved: 2026-09-01T16:17:43.078Z

Link: CVE-2026-84298

cve-icon Vulnrichment

Updated: 2026-09-21T18:49:11.197Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T16:17:24.803

Modified: 2026-09-23T18:26:49.087

Link: CVE-2026-84298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T18:15:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization