Logging Configuration Vulnerability in Hydra Framework by the Hydra Ecosystem
CVE-2026-106441

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106441?

The Hydra framework has a vulnerability that allows attackers to exploit its logging configuration, which is passed to logging.config.dictConfig(). In versions before 1.3.6 and 1.4.0.dev9, Hydra fails to enforce its target policy on handler class values and related components. This oversight allows a malicious actor to control the Hydra logging configuration, selecting importable classes or factory methods to execute with the application's privileges, thereby posing a significant security risk. The issue has been rectified in the latest versions.

Affected Version(s)

hydra < 1.3.6 < 1.3.6

hydra >= 1.4.0.dev0, < 1.4.0.dev9 < 1.4.0.dev0, 1.4.0.dev9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.