GHSA-r9w3-57w2-gch2
Ory Hydra has a SQL injection via forged pagination tokens
Quick fix
GHSA-r9w3-57w2-gch2 — github.com/ory/hydra/v2: upgrade to the fixed version with the command below.
go get github.com/ory/hydra/v2@v2.3.1-0.20260320110106-0b84568fffccDetails
## Description
Following Admin APIs in Ory Hydra are vulnerable to SQL injection due to flaws in its pagination implementation:
- listOAuth2Clients - listOAuth2ConsentSessions - listTrustedOAuth2JwtGrantIssuers
Pagination tokens are encrypted using the secret configured in `secrets.pagination`. If this value is not set, Hydra falls back to using `secrets.system`. An attacker who knows this secret can craft their own tokens, including malicious tokens that lead to SQL injection.
## Preconditions
This issue can be exploited when the following conditions are met:
- One or more **admin APIs** listed above are directly or indirectly accessible to the attacker - The attacker can pass a raw pagination token to the affected API - The configuration value `secrets.pagination` is set and known to the attacker, or `secrets.pagination` is not set and `secrets.system` is known to the attacker
## Impact
An attacker can execute arbitrary SQL queries through forged pagination tokens.
## Mitigation
As a first line of defense, immediately configure a custom value for `secrets.pagination` by generating a cryptographically secure random secret, for example:
``` openssl rand -base64 32 ```
Next, upgrade **Hydra** to the fixed version **as soon as possible**.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for github.com/ory/hydra (go modules). Pin to a known-safe version or switch to an alternative.
0Fixed in: 2.3.1-0.20260320110106-0b84568fffccgo get github.com/ory/hydra/v2@v2.3.1-0.20260320110106-0b84568fffcc