First published: Tue Apr 15 2025(Updated: )
Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could potentially access secrets that are accessible by the hydra user/group. This should not affect the signing keys, that are owned by the hydra-queue-runner and hydra-www users respectively.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
ORY Hydra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32435 is classified as a moderate severity vulnerability.
To address CVE-2025-32435, ensure you are using the latest version of Hydra with updated security patches.
The risks of CVE-2025-32435 include potential unauthorized access to sensitive secrets accessed by the hydra user/group.
CVE-2025-32435 affects the Hydra Continuous Integration service for Nix based projects.
To determine if your system is vulnerable to CVE-2025-32435, check your Hydra installation for untrusted non-flake Nix code evaluation.