CVE-2026-106442: fallo de gravedad alta en hydra-ecosystem hydra
Hydra instantiate target blacklist bypasses permit code execution
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.8epss 0.2%
probabilidad de explotación
0.2%top 95% de las CVE
explotación observada
noninguna fuente lo reporta
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization through pickle.loads, aliases, callable-returning helpers, generic dispatch, and deferred calls can obscure or defer the effective target and bypass name-based authorization. An attacker who causes an application to instantiate untrusted Hydra configuration can use these gaps to execute code with the application's privileges. This issue is fixed in versions 1.3.6 and 1.4.0.dev9.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Productos afectados
hydra-ecosystem · hydraCVEs relacionadas — hydra-ecosystem hydra
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-106439HIGHHydra: Mutable instantiate policy sets allow target blocklist bypassEPSS 0.5%CVE-2026-106440HIGHHydra: Optuna custom_search_space can resolve and execute untrusted callables via get_methodEPSS 0.3%CVE-2026-106441HIGHHydra logging configuration permits unsafe callable resolutionEPSS 0.2%
Referencias
https://github.com/hydra-ecosystem/hydra/commit/2c82bbb3f39603b336cb852461739fdf7a38798ahttps://github.com/hydra-ecosystem/hydra/commit/f462811117b5ecfd2ed652ed52d6b4e3771bd943https://github.com/hydra-ecosystem/hydra/pull/3412https://github.com/hydra-ecosystem/hydra/pull/3413https://github.com/hydra-ecosystem/hydra/releases/tag/v1.3.6https://github.com/hydra-ecosystem/hydra/security/advisories/GHSA-rqx7-p7vv-w7hr