GHSA-c3wx-c55w-pxjq

Suggest an improvement
Source
https://github.com/advisories/GHSA-c3wx-c55w-pxjq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-c3wx-c55w-pxjq/GHSA-c3wx-c55w-pxjq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c3wx-c55w-pxjq
Aliases
Published
2026-10-07T18:03:55Z
Modified
2026-10-07T18:15:12Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Hydra logging configuration permits unsafe callable resolution
Details

Summary

Hydra passed its Python logging configuration to logging.config.dictConfig(). Python's logging configurator can resolve and invoke importable classes and factories named by configuration, including handler class values and formatter, filter, handler, queue, and listener () factories.

This logging path was not mediated by Hydra's target policy. In versions that already protected instantiate(), logging resolution bypassed those controls because it did not use instantiate().

An attacker who can control a Hydra logging configuration can use a custom class or factory to execute code with the application's privileges when Hydra configures logging.

Fix

Hydra now applies its target policy to callable resolution and invocation in Hydra-configured Python logging. It authorizes custom factories, handlers, formatters, filters, queues, listeners, aliases, discovery results, and callable results before they can be used.

Hydra 1.3.6 uses the hardened blacklist. The Hydra 1.3 blacklist is a best-effort, defense-in-depth measure. It is not a complete security boundary and does not make untrusted logging configuration safe.

Hydra 1.4.0.dev9 introduces the execution whitelist as the recommended primary boundary, with the blacklist retained as a deprecated compatibility fallback. When an execution whitelist is supplied, Hydra automatically permits targets used by its built-in logging configurations, while custom logging integrations must be explicitly authorized by trusted Python code. If no whitelist is supplied, Hydra warns and preserves legacy fallback behavior.

Remediation

Upgrade to Hydra 1.3.6, or to Hydra 1.4.0.dev9 or later when testing the 1.4 prerelease line.

On Hydra 1.3, do not compose logging configuration from untrusted sources. On Hydra 1.4 and later, constrain custom logging targets with a narrow execution whitelist supplied by trusted Python code. The execution whitelist controls callable selection; it is not general validation of all logging settings.

For Hydra 1.4 execution-whitelist configuration, see:

https://hydra.cc/docs/advanced/execution_whitelist/

Database specific
{
    "cwe_ids": [
        "CWE-94"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T18:03:55Z",
    "nvd_published_at": "2026-10-06T19:18:13Z",
    "severity": "HIGH"
}
References

Affected packages

PyPI / hydra-core

Package

Name
hydra-core
View open source insights on deps.dev
Purl
pkg:pypi/hydra-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.6

Affected versions

0.*
0.1.4
0.1.5rc1
0.1.5
0.9.0
0.10.0
0.11.0rc1
0.11.0
0.11.1rc1
0.11.1
0.11.2rc1
0.11.2
0.11.3
1.*
1.0.0rc1
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.1.0.dev1
1.1.0.dev2
1.1.0.dev3
1.1.0.dev4
1.1.0.dev5
1.1.0.dev6
1.1.0.dev7
1.1.0rc1
1.1.0
1.1.1
1.1.2.dev0
1.1.2
1.2.0.dev1
1.2.0.dev2
1.2.0.dev3
1.2.0.dev4
1.2.0.dev5
1.2.0
1.3.0.dev0
1.3.0.dev1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-c3wx-c55w-pxjq/GHSA-c3wx-c55w-pxjq.json"

PyPI / hydra-core

Package

Name
hydra-core
View open source insights on deps.dev
Purl
pkg:pypi/hydra-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.4.0.dev0
Fixed
1.4.0.dev9

Affected versions

1.*
1.4.0.dev1
1.4.0.dev3
1.4.0.dev4
1.4.0.dev5
1.4.0.dev6
1.4.0.dev8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-c3wx-c55w-pxjq/GHSA-c3wx-c55w-pxjq.json"