PT-2025-32685 · Hydra · Hydra

Published

2025-08-12

·

Updated

2025-08-12

·

CVE-2025-54864

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Hydra versions prior to commit f7bda02
Description: Hydra is a continuous integration service for Nix based projects. The /api/push-github and /api/push-gitea API endpoints were called by their respective forges without HTTP Basic authentication, despite featuring HMAC signing with a secret key. Triggering evaluations, particularly large ones, could lead to denial of service attacks on the host running the evaluator.
Recommendations: Update to commit f7bda02 or later. As a workaround, block access to the /api/push-github and /api/push-gitea API endpoints via a reverse proxy.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-54864
GHSA-QPQ3-646C-VGX9

Affected Products

Hydra