GHSA-g26x-m427-f48f

Suggest an improvement
Source
https://github.com/advisories/GHSA-g26x-m427-f48f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-g26x-m427-f48f/GHSA-g26x-m427-f48f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g26x-m427-f48f
Aliases
Published
2026-09-22T20:34:14Z
Modified
2026-09-22T21:00:07Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check
Details

Summary

The GET /api/v1/stable/durable-tasks/{durable-task} endpoint (listDurableEventLog) is missing tenant authorization validation, allowing any authenticated user to read durable task event logs from any tenant.

Impact

This CVE requires the attacker to successfully guess the target UUID. Any authenticated Hatchet user can read durable task event logs from any other tenant, exposing:

  • Task display names and workflow identifiers
  • User messages (may contain sensitive business data)
  • Wait conditions and branching logic
  • Timing information
Database specific
{
    "cwe_ids":  [
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-22T20:34:14Z",
    "nvd_published_at":  "2026-09-21T16:17:10Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/hatchet-dev/hatchet

Package

Name
github.com/hatchet-dev/hatchet
View open source insights on deps.dev
Purl
pkg:golang/github.com/hatchet-dev/hatchet

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.91.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-g26x-m427-f48f/GHSA-g26x-m427-f48f.json"