Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11469 | Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could potentially access secrets that are accessible by the hydra user/group. This should not affect the signing keys, that are owned by the hydra-queue-runner and hydra-www users respectively. |
Mon, 22 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nixos
Nixos hydra |
|
| CPEs | cpe:2.3:a:nixos:hydra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nixos
Nixos hydra |
Wed, 16 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Apr 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could potentially access secrets that are accessible by the hydra user/group. This should not affect the signing keys, that are owned by the hydra-queue-runner and hydra-www users respectively. | |
| Title | Hydra no restricted eval after nix-eval-jobs migration | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-16T13:32:55.159Z
Reserved: 2025-04-08T10:54:58.368Z
Link: CVE-2025-32435
Updated: 2025-04-16T13:32:51.634Z
Status : Analyzed
Published: 2025-04-15T23:15:42.983
Modified: 2025-09-22T14:56:23.283
Link: CVE-2025-32435
No data.
OpenCVE Enrichment
No data.
EUVD