H
Hydra
Security Risk Profile
65
/100
highSecurity Risk Score
Comprehensive risk assessment based on 4 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 15, 2025 to present
4
Total CVEs
3
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
65/100
high
🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
0High
3Medium
0Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Code Injection
1
2
XSS
1
Most Affected Products
1. Hydra Hydra3
2. NixOS Hydra3
3. Hydra hydra.utils.instantiate1
4. pip/hydra-core1
Recent Vulnerabilities
See more →CVE-2026-68508
CVSS 7.8high
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
Aug 21, 2026
CVE-2025-54864
CVSS 7.5high
Hydra missing authentication when triggering evaluations through GitHub and Gitea plugins
Aug 12, 2025
CVE-2025-54800
CVSS 7.1high
Hydra persistent XSS in build metrics
Aug 12, 2025
CVE-2025-32435
CVSS 2.6EPSS 0%low
Hydra no restricted eval after nix-eval-jobs migration
Apr 15, 2025
Monitor Hydra in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.