Sceawere

Vulnerability Detail

CVE-2026-108755UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hatchet Resource Exhaustion Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
hatchet-dev
Product
hatchet
Attack Type
Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Hatchet through 0.110.5 contains an allocation of resources without limits vulnerability that allows unauthenticated attackers to exhaust memory via the SNS ingestion endpoint. Attackers can send arbitrarily large or concurrent request bodies to POST /api/v1/sns/{tenant}/{event} with any UUID, which the SnsUpdate handler buffers before signature verification, degrading availability.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-11T13:17:20.517Z",
  "pubdate": "2026-10-11T13:17:20.517Z",
  "executiveSummary": "Hatchet versions up to and including 0.110.5 are susceptible to a resource exhaustion vulnerability categorized as an allocation of resources without limits.\nThe vulnerability resides in the SNS ingestion endpoint, specifically affecting the handling of incoming POST requests.\nUnauthenticated remote attackers can leverage this flaw to exhaust server memory by transmitting arbitrarily large or highly concurrent request bodies to the /api/v1/sns/{tenant}/{event} endpoint.\nBecause the SnsUpdate handler performs payload buffering prior to verifying cryptographic signatures, the application becomes vulnerable to denial-of-service (DoS) attacks.\nSuccessful exploitation results in significant degradation of service availability. There are no authentication requirements for an attacker to initiate this attack, making it a critical threat to system stability and uptime for deployments utilizing the SNS ingestion feature.",
  "technicalDetails": "The vulnerability is rooted in an improper implementation of request body management within the SnsUpdate handler of the Hatchet application. Specifically, the system fails to impose size constraints or rate-limiting mechanisms on the incoming request payload before initiating memory allocation.\nWhen a POST request is directed to the /api/v1/sns/{tenant}/{event} endpoint, the SnsUpdate handler is invoked to process the data. The design flaw necessitates that the entire request body be read into memory to facilitate signature verification; however, this buffering process occurs without validating the content length or total memory consumption.\nAn unauthenticated attacker can exploit this by sending a request with an abnormally large body or by flooding the endpoint with a high volume of concurrent requests. Because the SnsUpdate handler allocates memory to store these buffers for each request, the server's available system memory is rapidly consumed.\nThe attack flow follows a predictable pattern: 1) The attacker initiates an HTTP POST request to the target SNS endpoint using an arbitrary UUID as the event identifier. 2) The server accepts the connection and begins buffering the payload into memory to prepare for the subsequent signature validation process. 3) By sending multi-gigabyte payloads or executing rapid-fire concurrent requests, the attacker triggers an out-of-memory (OOM) state or forces the garbage collector into a critical performance bottleneck.\nThis vulnerability is particularly impactful because the resource allocation occurs at the edge of the application logic, bypassing the intended security controls that require valid cryptographic signatures. Since the signature check is only performed post-buffering, the authentication mechanism fails to protect the system from this category of resource exhaustion. Affected versions include all releases up to and including 0.110.5. The impact is a total or partial loss of availability, as the host system may experience process crashes or system-wide resource contention that impacts other co-located services."
}
CVE-2026-108755: Hatchet Resource Exhaustion Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere