CNNVD-202506-2586 Information

CNNVD ID

CNNVD-202506-2586

CVE-2025-48886

  • CNNVD Published: 2025-06-19

Description (Chinese)

Hydra是Nix开源的一个基于Nix项目的持续集成服务。 Hydra 0.22.0之前版本存在安全漏洞,该漏洞源于未考虑Cardano L1上的失败交易,可能导致重组织攻击。

Description (English)

Hydra is a continuous integration service based on the Nix project, which is an open source for Nix. There was a security loophole in the pre-Hydra 0.22.0 version, which stemmed from failure to take into account failed deals on Cardano L1, which could lead to heavy organizational attacks.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Nix

Published

2025-06-19

Last Modified

2026-02-24

References

https://nvd.nist.gov/vuln/detail/CVE-2025-48886

Patch

https://github.com/cardano-scaling/hydra/releases

Share on: