VDB
Sign up
HIGH7.2

GHSA-r9w3-57w2-gch2

Ory Hydra has a SQL injection via forged pagination tokens

Quick fix

GHSA-r9w3-57w2-gch2 — github.com/ory/hydra/v2: upgrade to the fixed version with the command below.

go get github.com/ory/hydra/v2@v2.3.1-0.20260320110106-0b84568fffcc

Details

## Description

Following Admin APIs in Ory Hydra are vulnerable to SQL injection due to flaws in its pagination implementation:

- listOAuth2Clients - listOAuth2ConsentSessions - listTrustedOAuth2JwtGrantIssuers

Pagination tokens are encrypted using the secret configured in `secrets.pagination`. If this value is not set, Hydra falls back to using `secrets.system`. An attacker who knows this secret can craft their own tokens, including malicious tokens that lead to SQL injection.

## Preconditions

This issue can be exploited when the following conditions are met:

- One or more **admin APIs** listed above are directly or indirectly accessible to the attacker - The attacker can pass a raw pagination token to the affected API - The configuration value `secrets.pagination` is set and known to the attacker, or `secrets.pagination` is not set and `secrets.system` is known to the attacker

## Impact

An attacker can execute arbitrary SQL queries through forged pagination tokens.

## Mitigation

As a first line of defense, immediately configure a custom value for `secrets.pagination` by generating a cryptographically secure random secret, for example:

``` openssl rand -base64 32 ```

Next, upgrade **Hydra** to the fixed version **as soon as possible**.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/ory/hydra
Introduced in: 0

No fixed version published yet for github.com/ory/hydra (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/ory/hydra/v2
Introduced in: 0Fixed in: 2.3.1-0.20260320110106-0b84568fffcc
Fixgo get github.com/ory/hydra/v2@v2.3.1-0.20260320110106-0b84568fffcc

References