CVE-2025-32435

Name
CVE-2025-32435
Description
Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could potentially access secrets that are accessible by the hydra user/group. This should not affect the signing keys, that are owned by the hydra-queue-runner and hydra-www users respectively.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/NixOS/hydra/commit/8d750265135b7e203520036a742afdf301b4013f
CONFIRM https://github.com/NixOS/hydra/security/advisories/GHSA-j7w7-965w-vjxw
MISC https://github.com/NixOS/nixpkgs/pull/397919
MISC https://github.com/nix-community/nix-eval-jobs/releases/tag/v2.28.1

Match rules

CPE URI Source package Min version Max version
hydra >= 0 < 8d750265135b7e203520036a742afdf301b4013f
cpe:2.3:a:nixos:hydra:*:*:*:*:*:*:*:* hydra >= None < 2025-04-11

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
hydra edge-community 9.6-r1 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
hydra edge-community 9.6-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
hydra edge-community 9.5-r1 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
hydra 3.22-community 9.5-r1 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable