GO-2026-4861
Dashboard / Vulnerabilities / GO-2026-4861
GO-2026-4861
Summary: Hydra has Reflected XSS via error_hint parameter in github.com/ory/hydra
Details: Hydra has Reflected XSS via error_hint parameter in github.com/ory/hydra. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/ory/hydra before v1.4.8.
References: https://github.com/advisories/GHSA-7v6r-w4r6-mhch, https://nvd.nist.gov/vuln/detail/CVE-2019-8400, https://github.com/ory/hydra/commit/9b5bbd48a72096930af08402c5e07fce7dd770f3, https://drive.google.com/file/d/1-25expUYVfK6vsiCmEabUCuelOP7aUDj/view?usp=drivesdk, https://github.com/ory/hydra/blob/master/CHANGELOG.md#v100-rc3oryos9-2018-12-06, https://hackerone.com/reports/456333, https://www.youtube.com/watch?v=RIyZLeKEC8E
Affected packages
Package
Name: github.com/ory/hydra
Purl: pkg:golang/github.com/ory/hydra
Affected ranges
Type: SEMVER
Events:
