Execution Policy Vulnerability in Hydra Framework by Hydra Ecosystem
CVE-2026-106439

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106439?

The Hydra Framework has a vulnerability that allows attackers to manipulate the mutable module-level state, resulting in a potential code execution scenario. Specifically, from versions 1.3.4 to 1.3.7 and 1.4.0.dev10, the application allows an attacker controlling sibling target entries to exploit the hydra._internal.target_policy.UNCONTROLLED_EXECUTION_TARGETS.discard attribute through the instantiate() method. This results in the removal of a denied target, enabling its invocation. Given that the mutation persists across a global state, the application could execute harmful code with its own privileges. The issue is resolved in versions 1.3.7 and 1.4.0.dev10, making it crucial for users to update to these latest releases.

Affected Version(s)

hydra >= 1.3.4, < 1.3.7 < 1.3.4, 1.3.7

hydra >= 1.4.0.dev4, < 1.4.0.dev10 < 1.4.0.dev4, 1.4.0.dev10

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.