GHSA-g26x-m427-f48f: Medium severity go/github.com/hatchet-dev/hatchet vulnerability

Published Sep 22, 2026
·
Updated

Summary

The GET /api/v1/stable/durable-tasks/{durable-task} endpoint (listDurableEventLog) is missing tenant authorization validation, allowing any authenticated user to read durable task event logs from any tenant.

Impact This CVE requires the attacker to successfully guess the target UUID. Any authenticated Hatchet user can read durable task event logs from any other tenant, exposing: - Task display names and workflow identifiers - User messages (may contain sensitive business data) - Wait conditions and branching logic - Timing information

Affected Software

1 affected componentFixes available
go/github.com/hatchet-dev/hatchet<0.91.1
0.91.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/hatchet-dev/hatchet to a version that resolves this vulnerability.

    Fixed in 0.91.1

Event History

Sep 22, 2026
Advisory Published
via GitHub·08:34 PM
Data Sourced
via GitHub·08:34 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated Hatchet user can exploit it. The attacker must successfully guess the UUID of a durable task belonging to another tenant.

2

What information could be exposed?

An attacker can read durable task event logs from other tenants. These logs can expose task display names, workflow identifiers, user messages, wait conditions, branching logic, and timing information.

3

Is an unauthenticated attacker affected by this issue?

No. Exploitation requires an authenticated Hatchet user account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203