go package report

Is github.com/ory/hydra/v2 safe?

1 known vulnerability, worst severity HIGH.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


      cvss
      0.0
      high

      severity out of 10

      epss
      0.00%
      medium

      chance of exploitation in 30 days, 36th percentile of all CVEs

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-r9w3-57w2-gch2, the advisory selected below

      // 1 advisories

      GHSA-r9w3-57w2-gch2

      HIGHCVE-2026-33504
      // description

      Following Admin APIs in Ory Hydra are vulnerable to SQL injection due to flaws in its pagination implementation:

      • listOAuth2Clients
      • listOAuth2ConsentSessions
      • listTrustedOAuth2JwtGrantIssuers

      Pagination tokens are encrypted using the secret configured in secrets.pagination. If this value is not set, Hydra falls back to using secrets.system. An attacker who knows this secret can craft their own tokens, including malicious tokens that lead to SQL injection.

      // preconditions

      This issue can be exploited when the following conditions are met:

      • One or more admin APIs listed above are directly or indirectly accessible to the attacker
      • The attacker can pass a raw pagination token to the affected API
      • The configuration value secrets.pagination is set and known to the attacker, or secrets.pagination is not set and secrets.system is known to the attacker
      // impact

      An attacker can execute arbitrary SQL queries through forged pagination tokens.

      // mitigation

      As a first line of defense, immediately configure a custom value for secrets.pagination by generating a cryptographically secure random secret, for example:

      openssl rand -base64 32

      Next, upgrade Hydra to the fixed version as soon as possible.

      // cvss v3.1 vector

      CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

      Attack vector
      Network
      Attack complexity
      Low
      Privileges required
      High
      User interaction
      None
      Scope
      Unchanged
      Confidentiality
      High
      Integrity
      High
      Availability
      High

      Checked 2026-10-01 at 00:02 UTC. The most recent advisory here was published 2026-03-20. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.