CVE-2026-106442
Received Received - Intake

Code Execution in Hydra Framework via Target Blacklist Bypass

Vulnerability report for CVE-2026-106442, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization through pickle.loads, aliases, callable-returning helpers, generic dispatch, and deferred calls can obscure or defer the effective target and bypass name-based authorization. An attacker who causes an application to instantiate untrusted Hydra configuration can use these gaps to execute code with the application's privileges. This issue is fixed in versions 1.3.6 and 1.4.0.dev9.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
hydra-ecosystem hydra >= 1.3.4, < 1.3.6
hydra-ecosystem hydra >= 1.4.0.dev0, < 1.4.0.dev9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Hydra versions 1.3.4 to 1.3.6 and 1.4.0.dev9 have a flaw in the instantiate() target blacklist. The blacklist fails to properly check the actual callable function selected by the target field, allowing execution wrappers, deserialization, aliases, and deferred calls to bypass authorization checks. This enables attackers to execute arbitrary code with the application's privileges by providing untrusted Hydra configuration.

Impact Analysis

If you use Hydra in your application, an attacker could exploit this to run malicious code on your system with the same permissions as your application. This could lead to data theft, system compromise, or further network infiltration depending on the application's privileges.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially causing data breaches or loss of sensitive information. Such incidents may violate compliance requirements under GDPR (data protection), HIPAA (health data security), or other regulations, resulting in legal penalties, reputational damage, and mandatory breach notifications.

Mitigation Strategies

Upgrade Hydra to version 1.3.6 or 1.4.0.dev9 or later to address the vulnerability. Review any untrusted Hydra configurations to ensure they do not contain code execution vectors.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106442. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart