Affected by GO-2026-6309
and 4 other vulnerabilities
GO-2026-6309: Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet
GO-2026-6560: Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter in github.com/hatchet-dev/hatchet
GO-2026-6561: Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher in github.com/hatchet-dev/hatchet
GO-2026-6565: Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler in hatchet-dev/hatchet
GO-2026-6567: Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check in github.com/hatchet-dev/hatchet
Middleware returns an echo middleware that handles CORS for all requests.
If AllowedOrigins is configured in the server runtime config, the request Origin header is
matched against each pattern using wildcard glob syntax (e.g. "https://*.example.com").
On a match, Access-Control-Allow-Origin is set to the exact origin value from the request.
On no match for an OPTIONS preflight, 403 is returned. For other methods the request
proceeds without the header, leaving the browser to enforce the same-origin policy.
If AllowedOrigins is empty (not configured), Access-Control-Allow-Origin is set to "*",
preserving the previous open behaviour.