CVE-2026-106442

Source
https://cve.org/CVERecord?id=CVE-2026-106442
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106442.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-106442
Aliases
Published
2026-10-06T18:55:49Z
Modified
2026-10-08T02:51:18Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Hydra instantiate target blacklist bypasses permit code execution
Details

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization through pickle.loads, aliases, callable-returning helpers, generic dispatch, and deferred calls can obscure or defer the effective target and bypass name-based authorization. An attacker who causes an application to instantiate untrusted Hydra configuration can use these gaps to execute code with the application's privileges. This issue is fixed in versions 1.3.6 and 1.4.0.dev9.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-184"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106442.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.4.0.dev0"
                },
                {
                    "fixed": "1.4.0.dev9"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/hydra-ecosystem/hydra

Affected ranges

Type
GIT
Repo
https://github.com/hydra-ecosystem/hydra
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.3.4"
        },
        {
            "fixed": "1.3.6"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.3.4
v1.3.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106442.json"