7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/hatchet-dev/hatchet is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.3
CVE-2026-63342
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check
LOW 3.1
CVE-2026-84298
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
MEDIUM 4.3
CVE-2026-88978
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
MEDIUM 6.4
CVE-2026-54746
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
UNKNOWN
CVE-2026-54746
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet
MEDIUM 5.3
CVE-2026-42572
Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds`
UNKNOWN
CVE-2026-42572
Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds` in github.com/hatchet-dev/hatchet
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes