CVE-2026-106440
Received Received - Intake

Code Execution in Hydra Framework via Optuna Sweeper

Vulnerability report for CVE-2026-106440, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hydra.utils.get_method(), and later invokes the returned callable in the Hydra controller process. Because get_method() is a trusted-input lookup helper and does not apply the execution policy used by instantiate(), an attacker who controls Optuna sweep configuration or command-line overrides can select importable Python code for execution with the application's privileges, including bypassing a trusted execution whitelist on affected Hydra 1.4 development releases. This issue is fixed in versions 1.3.0 and 1.4.0.dev10.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
hydra-ecosystem hydra >= 1.2.0, < 1.3.0
hydra-ecosystem hydra >= 1.4.0.dev4, < 1.4.0.dev10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-470 The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Hydra framework allows an attacker who controls Optuna sweep configuration or command-line overrides to execute arbitrary Python code with the application's privileges. The issue arises because the hydra-optuna-sweeper package uses a trusted-input lookup helper that does not enforce execution policies, enabling code execution bypassing whitelists in affected versions.

Impact Analysis

An attacker could exploit this to run malicious code on your system with the same permissions as the Hydra application. This could lead to data theft, system compromise, or unauthorized actions depending on the application's privileges.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations using affected Hydra versions may face compliance violations and potential penalties.

Mitigation Strategies

Upgrade Hydra to version 1.3.0 or later, or 1.4.0.dev10 if using a development release. This addresses the issue by applying proper execution policies to prevent arbitrary code execution via configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106440. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart