Hydra 是一个用于优雅地配置复杂应用程序的框架。在 1.3.4 至 1.3.6 以及 1.4.0.dev9 版本之间,为应对 CVE-2026-68508 而引入的 目标黑名单,未能完整验证由 字段最终确定的可调用对象。诸如 等执行包装器、通过 实现的二进制数据反序列化、别名、返回可调用的辅助函数、通用分发机制以及延迟调用等机制,可能隐藏或延迟实际的目标对象,从而绕过基于名称的授权检查。攻击者若能使应用程序实例化不受信任的 Hydra 配置,即可利用这些缺陷以应用程序的权限执行任意代码。该问题已在 1.3.6
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| hydra-ecosystem | hydra | >= 1.3.4, < 1.3.6 |
affected |
>= 1.4.0.dev0, < 1.4.0.dev9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| hydra-ecosystem | hydra | >= 1.3.4, < 1.3.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106439 | 8.5 HIGH | Hydra: Mutable instantiate policy sets allow target blocklist bypass |
| CVE-2026-106440 | 7.8 HIGH | Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_meth |
| CVE-2026-106441 | 7.8 HIGH | Hydra logging configuration permits unsafe callable resolution |
No comments yet