Home/Product/nixos hydra
Product

nixos hydra

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-33504
< 26.2.0
Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2ConsentSes
7.2HIGH
CVE-2025-54864
< 2025-08-12
Hydra is a continuous integration service for Nix based projects. Prior to commit f7bda02, /api/push-github and /api/push-gitea ar
7.5HIGH
CVE-2025-54800
< 2025-08-12
Hydra is a continuous integration service for Nix based projects. Prior to commit dea1e16, a malicious package can introduce arbit
6.1MEDIUM
CVE-2025-32435
< 2025-04-11
Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could potentially acc
2.6LOW
CVE-2024-45049
< 2024-08-27
Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authe
7.5HIGH
CVE-2024-32657
< 23.11
Hydra is a Continuous Integration service for Nix based projects. Attackers can execute arbitrary code in the browser context of H
4.6MEDIUM
CVE-2023-42449
< 0.13.0
Hydra is the two-layer scalability solution for Cardano. Prior to version 0.13.0, it is possible for a malicious head initializer
8.1HIGH
CVE-2023-42448
< 0.13.0
Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the contestation p
8.1HIGH
CVE-2023-38701
< 0.12.0
Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to commit into
9.1CRITICAL
CVE-2023-42806
< 0.13.0
Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying $\mathsf{cid}$ allow
6.5MEDIUM
CVE-2020-5300
< 1.4.0
In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, when usi
5.8MEDIUM
CVE-2019-17502
<= 0.1.8
Hydra through 0.1.8 has a NULL pointer dereference and daemon crash when processing POST requests that lack a Content-Length heade
7.5HIGH
CVE-2019-8400
all versions
ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.
6.1MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin