Execution Policy Vulnerability in Hydra Framework by Hydra Ecosystem
CVE-2026-106439
What is CVE-2026-106439?
The Hydra Framework has a vulnerability that allows attackers to manipulate the mutable module-level state, resulting in a potential code execution scenario. Specifically, from versions 1.3.4 to 1.3.7 and 1.4.0.dev10, the application allows an attacker controlling sibling target entries to exploit the hydra._internal.target_policy.UNCONTROLLED_EXECUTION_TARGETS.discard attribute through the instantiate() method. This results in the removal of a denied target, enabling its invocation. Given that the mutation persists across a global state, the application could execute harmful code with its own privileges. The issue is resolved in versions 1.3.7 and 1.4.0.dev10, making it crucial for users to update to these latest releases.
Affected Version(s)
hydra >= 1.3.4, < 1.3.7 < 1.3.4, 1.3.7
hydra >= 1.4.0.dev4, < 1.4.0.dev10 < 1.4.0.dev4, 1.4.0.dev10
