Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106439— Hydra: Mutable instantiate policy sets allow target blocklist bypass

Quick assessment

Affected
hydra-ecosystem hydra
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Hydra 是一个用于优雅配置复杂应用程序的框架。从 1.3.4 到 1.3.7(含)以及 1.4.0.dev10 版本中,Hydra 将旧的 instantiate 目标阻止列表及相关执行策略集合存储在可变的模块级状态中。攻击者若控制了多个同级的目标(target)条目,便可以通过 方法调用 ,从而移除被拒绝的目标,并在同级节点按照插入顺序处理同一份被篡改策略的情况下,成功调用该目标。该突变会持久化到进程全局状态中,可能导致以应用程序权限执行任意代码;然而,通过可信 Python 代码提供的狭窄执行白名单,并未因

CVSS 8.5 · High

Possible ATT&CK Techniques 1 AI

T1055 · Process Injection

Affected Version Matrix 2

VendorProduct Version RangeStatus
hydra-ecosystem hydra >= 1.3.4, < 1.3.7 affected
>= 1.4.0.dev4, < 1.4.0.dev10 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106439

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hydra: Mutable instantiate policy sets allow target blocklist bypass
Source: CVE Program / CVE List V5
Vulnerability Description
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An attacker who controls multiple sibling target entries can resolve hydra._internal.target_policy.UNCONTROLLED_EXECUTION_TARGETS.discard through instantiate(), remove a denied target, and then invoke that target because sibling nodes are processed in insertion order against the same modified policy. The mutation persists in process-global state and can enable code execution with the application's privileges, while a narrow execution whitelist supplied by trusted Python code is not bypassed by the reported direct mutation path. This issue is fixed in versions 1.3.7 and 1.4.0.dev10.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用外部可控制的输入来选择类或代码(不安全的反射)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
hydra-ecosystem hydra >= 1.3.4, < 1.3.7 -

II. Public POCs for CVE-2026-106439

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106439

请登录查看更多情报信息。

Other References for CVE-2026-106439 (4)

Same Patch Batch · hydra-ecosystem · 2026-10-06 · 4 CVEs total

CVE-2026-106440 7.8 HIGH Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_meth
CVE-2026-106442 7.8 HIGH Hydra instantiate target blacklist bypasses permit code execution
CVE-2026-106441 7.8 HIGH Hydra logging configuration permits unsafe callable resolution

IV. Related Vulnerabilities

V. Comments for CVE-2026-106439

No comments yet


Leave a comment