CVE-2026-106441: falha de alta gravidade em hydra-ecosystem hydra
Hydra logging configuration permits unsafe callable resolution
Publicada em · Atualizada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.8epss 0.2%
probabilidade de exploração
0.2%top 95% das CVEs
exploração observada
nãonenhuma fonte reporta
Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatter, filter, handler, queue, and listener factories. An attacker who controls Hydra logging configuration can therefore select an importable class or factory and cause it to be invoked with the application's privileges, even in versions where instantiate() is protected because the logging path does not use instantiate(). This issue is fixed in versions 1.3.6 and 1.4.0.dev9.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Produtos afetados
hydra-ecosystem · hydraCVEs relacionadas — hydra-ecosystem hydra
No mesmo produto, das mais perigosas para as menos.
CVE-2026-106439HIGHHydra: Mutable instantiate policy sets allow target blocklist bypassEPSS 0.5%CVE-2026-106440HIGHHydra: Optuna custom_search_space can resolve and execute untrusted callables via get_methodEPSS 0.3%CVE-2026-106442HIGHHydra instantiate target blacklist bypasses permit code executionEPSS 0.2%
Referências
https://github.com/hydra-ecosystem/hydra/commit/76bfc30ce1f3105416941dd2e3a562568e369120https://github.com/hydra-ecosystem/hydra/commit/ff3e4dba890c29a21d8c2bb867ee87d37ccf21d0https://github.com/hydra-ecosystem/hydra/pull/3420https://github.com/hydra-ecosystem/hydra/security/advisories/GHSA-c3wx-c55w-pxjq