CVE-2026-108755
Deferred Deferred - Pending Action

Memory Exhaustion in Hatchet via SNS Ingestion Endpoint

Vulnerability report for CVE-2026-108755, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Hatchet through 0.110.5 contains an allocation of resources without limits vulnerability that allows unauthenticated attackers to exhaust memory via the SNS ingestion endpoint. Attackers can send arbitrarily large or concurrent request bodies to POST /api/v1/sns/{tenant}/{event} with any UUID, which the SnsUpdate handler buffers before signature verification, degrading availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hatchet-dev hatchet 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an allocation of resources without limits issue in Hatchet through version 0.110.5. It allows unauthenticated attackers to send large or concurrent request bodies to the SNS ingestion endpoint POST /api/v1/sns/{tenant}/{event}. The SnsUpdate handler buffers these requests in memory before performing signature verification, which can exhaust server memory and degrade system availability.

Detection Guidance

Monitor for unusually high memory usage on the Hatchet server, particularly when processing POST requests to /api/v1/sns/{tenant}/{event}. Check for large or concurrent request bodies being sent to this endpoint without prior authentication or signature verification.

Impact Analysis

This vulnerability can lead to denial-of-service conditions by consuming excessive server memory. Attackers can send large or numerous requests to the vulnerable endpoint, causing the server to slow down or crash, which impacts system availability and performance.

Compliance Impact

This vulnerability primarily impacts availability by allowing unauthenticated memory exhaustion attacks. While it does not directly expose or alter data, prolonged unavailability could violate GDPR's availability principle (Article 32) requiring appropriate security measures for personal data processing. For HIPAA, it may affect the availability of systems handling protected health information if Hatchet is used in healthcare workflows.

Mitigation Strategies
  • Upgrade Hatchet to a version beyond 0.110.5 where this issue is resolved.
  • Implement rate limiting on the SNS ingestion endpoint to prevent memory exhaustion from large requests.
  • Add body size restrictions to the POST /api/v1/sns/{tenant}/{event} endpoint to limit request payloads.
  • Enable authentication for the SNS ingestion endpoint to block unauthenticated requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108755. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart