CVE-2025-32435: Hydra no restricted eval after nix-eval-jobs migration
Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could potentially access secrets that are accessible by the hydra user/group. This should not affect the signing keys, that are owned by the hydra-queue-runner and hydra-www users respectively.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32435?
CVE-2025-32435 is classified as a moderate severity vulnerability.
How do I fix CVE-2025-32435?
To address CVE-2025-32435, ensure you are using the latest version of Hydra with updated security patches.
What are the risks associated with CVE-2025-32435?
The risks of CVE-2025-32435 include potential unauthorized access to sensitive secrets accessed by the hydra user/group.
Which software versions are affected by CVE-2025-32435?
CVE-2025-32435 affects the Hydra Continuous Integration service for Nix based projects.
How can I determine if my system is vulnerable to CVE-2025-32435?
To determine if your system is vulnerable to CVE-2025-32435, check your Hydra installation for untrusted non-flake Nix code evaluation.