GHSA-8x7x-83cf-c3pg
MODERATECVE-2026-54746A cross-tenant write / DoS vulnerability in the Hatchet Dispatcher gRPC service allows any holder of a normal tenant-scoped API token (the lowest credential Hatchet issues — an OWNER of a brand-new tenant) to overwrite the affinity labels of, or disconnect from the dispatcher, any worker UUID belonging to any other tenant on the same Hatchet instance. The two affected RPCs — Dispatcher/UpsertWorke
- Affected
- >=0.40.0, <0.91.2, >= 0.40.0, < 0.91.2
- Fixed in
- 0.91.2
- Weakness
- CWE-639
- Published
- 2026-08-28
- Source
- osv