Hydra 是一个用于优雅配置复杂应用程序的框架。从 1.3.4 到 1.3.7(含)以及 1.4.0.dev10 版本中,Hydra 将旧的 instantiate 目标阻止列表及相关执行策略集合存储在可变的模块级状态中。攻击者若控制了多个同级的目标(target)条目,便可以通过 方法调用 ,从而移除被拒绝的目标,并在同级节点按照插入顺序处理同一份被篡改策略的情况下,成功调用该目标。该突变会持久化到进程全局状态中,可能导致以应用程序权限执行任意代码;然而,通过可信 Python 代码提供的狭窄执行白名单,并未因
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| hydra-ecosystem | hydra | >= 1.3.4, < 1.3.7 |
affected |
>= 1.4.0.dev4, < 1.4.0.dev10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| hydra-ecosystem | hydra | >= 1.3.4, < 1.3.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106440 | 7.8 HIGH | Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_meth |
| CVE-2026-106442 | 7.8 HIGH | Hydra instantiate target blacklist bypasses permit code execution |
| CVE-2026-106441 | 7.8 HIGH | Hydra logging configuration permits unsafe callable resolution |
No comments yet