Hydra 是一个用于优雅配置复杂应用程序的框架。在版本 1.3.6 及之前,以及 1.4.0.dev9 之前,Hydra 将 Python 的日志配置直接传递给 logging.config.dictConfig(),但未对处理器(handler)类值以及格式化器(formatter)、过滤器(filter)、处理器(handler)、队列(queue)和监听器(listener)工厂应用 Hydra 的实例化策略(target policy)。因此,如果攻击者能够控制 Hydra 的日志配置,便可以选择一个可导
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| hydra-ecosystem | hydra | < 1.3.6 |
affected |
>= 1.4.0.dev0, < 1.4.0.dev9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| hydra-ecosystem | hydra | < 1.3.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106439 | 8.5 HIGH | Hydra: Mutable instantiate policy sets allow target blocklist bypass |
| CVE-2026-106440 | 7.8 HIGH | Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_meth |
| CVE-2026-106442 | 7.8 HIGH | Hydra instantiate target blacklist bypasses permit code execution |
No comments yet