Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

hydra — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in hydra, with AI-generated Chinese analysis, references, and POCs.

This page documents common vulnerabilities and general weakness classifications associated with the Hydra product, a widely used multi-threaded login attack tool. It aggregates data covering security advisories, vulnerability disclosures, and known exploitation scenarios that have emerged since the tool's initial release and continued through recent years. Users can utilize this resource to track historical advisory updates from security vendors, gain a deeper understanding of the specific weakness classes that frequently affect such security testing utilities, and review the chronological vulnerability history of the product to assess its evolution. The content is curated to provide technical clarity rather than promotional material, focusing on factual records of reported issues. By examining the aggregated entries, security professionals and developers can identify patterns in how these vulnerabilities were discovered, patched, or mitigated over time. This approach allows for a comprehensive view of the product's security landscape without relying on subjective assessments. The data serves as a reference point for evaluating the risk profile of using Hydra in various environments, helping users make informed decisions about its deployment and the necessary precautions. All information presented is derived from verified sources to ensure accuracy and reliability for those conducting security audits or researching software vulnerabilities.

Vendor: ory

CVE ID Title CVSS Severity Published
CVE-2026-68508 Hydra: hydra.utils.instantiate with untrusted config can lead to code execution CWE-94 7.8 High 2026-08-21
CVE-2026-33504 Ory Hydra has a SQL injection via forged pagination tokens CWE-89 7.2 High 2026-03-26
CVE-2025-54864 Hydra missing authentication when triggering evaluations through GitHub and Gitea plugins CWE-306 7.5AI High AI 2025-08-12
CVE-2025-54800 Hydra persistent XSS in build metrics CWE-79 6.1AI Medium AI 2025-08-12
CVE-2025-48886 hydra-node dangerously assumes L1 event finality and does not consider failed transactions CWE-755 4.8 Medium 2025-06-19
CVE-2025-32435 Hydra no restricted eval after nix-eval-jobs migration CWE-95 2.6 Low 2025-04-15
CVE-2024-45049 Nix Hydra Missing authentication when triggering evaluations CWE-306 7.5 High 2024-08-27
CVE-2024-32657 Hydra has persistent XSS vulnerability serving HTML build outputs CWE-79 4.6 Medium 2024-04-22
CVE-2023-42449 Malicious head initialiser can extract PTs from control of Hydra scripts, leading to locked participant commits or spoofed commits CWE-20 8.1 High 2023-10-04
CVE-2023-42448 Hydra's contestation period in head datum can be modified during Close transaction, allowing malicious participant to freely modify the contestation deadline CWE-20 8.1 High 2023-10-04
CVE-2023-38701 Hydra's committed UTxOs at Commit validator and UTxOs at Initial validator can be spent arbitrarily by anyone CWE-20 9.1 Critical 2023-10-04
CVE-2023-42806 Snapshot signature not including HeadID will allow replay attacks CWE-347 6.5 Medium 2023-09-21
CVE-2020-5300 Disallow replay of `private_key_jwt` by blacklisting JTIs in Hydra CWE-294 5.8 Medium 2020-04-06

All 13 known CVE vulnerabilities affecting hydra with full Chinese analysis, references, and POCs where available.