Skip to main content

Vendor/product archive

ory / hydra CVEs

Beta · best-effort

3 CVEs tagged to ory / hydra0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-33504

Published Mar 26, 2026

Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2ConsentSessions, and listTrustedOAuth2JwtGrantIssuers Admin…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-5300

Published Apr 6, 2020

In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, when using client authentication method 'private_key_jwt' […

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8400

Published Feb 17, 2019

ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1