Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Depending on the size of evaluations, this can impact the availability of systems. The problem can be fixed by applying https://github.com/NixOS/hydra/commit/f73043378907c2c7e44f633ad764c8bdd1c947d5 to any Hydra package. Users are advised to upgrade. Users unable to upgrade should deny the `/api/push` route in a reverse proxy. This also breaks the "Evaluate jobset" button in the frontend.
Conclusion & alert: CVE-2024-45049 is rated Moderate Risk (45.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.62%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.36% | 0.62% | +0.26% |
| 2 | 2025-11-21 | 0.60% | 0.36% | -0.24% |
| 3 | 2025-11-18 | — | 0.60% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-45049: 1 source package rows (hydra); 5 state rows across 3 repos (3.22-community, 3.23-community, edge-community); fixed 0, open 5. | https://security.alpinelinux.org/vuln/CVE-2024-45049 |
| URL | Tags |
|---|---|
| https://github.com/NixOS/hydra/commit/f73043378907c2c7e44f633ad764c8bdd1c947d5 | Patch |
| https://github.com/NixOS/hydra/security/advisories/GHSA-xv29-v93r-2f5v | Patch Vendor Advisory |
| https://github.com/NixOS/nixpkgs/pull/337766 | Issue Tracking Patch |
| https://mastodon.delroth.net/@delroth/113029832631860419 | Third Party Advisory |