Logging Configuration Vulnerability in Hydra Framework by the Hydra Ecosystem
CVE-2026-106441
7.8HIGH
What is CVE-2026-106441?
The Hydra framework has a vulnerability that allows attackers to exploit its logging configuration, which is passed to logging.config.dictConfig(). In versions before 1.3.6 and 1.4.0.dev9, Hydra fails to enforce its target policy on handler class values and related components. This oversight allows a malicious actor to control the Hydra logging configuration, selecting importable classes or factory methods to execute with the application's privileges, thereby posing a significant security risk. The issue has been rectified in the latest versions.
Affected Version(s)
hydra < 1.3.6 < 1.3.6
hydra >= 1.4.0.dev0, < 1.4.0.dev9 < 1.4.0.dev0, 1.4.0.dev9
