Code Execution Vulnerability in Hydra Framework by Hydra Ecosystem
CVE-2026-106442

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106442?

The Hydra Framework is susceptible to a code execution vulnerability due to inadequately enforced target checks for the instantiate() method. This occurs in versions 1.3.4 through 1.3.6 and 1.4.0.dev9, where the mechanisms used to sanitize the effective callable target can be circumvented. Attackers can exploit these weaknesses by causing the application to instantiate untrusted Hydra configurations, which may lead to unauthorized code execution with the application’s privileges. The issue is mitigated in later versions, specifically 1.3.6 and beyond.

Affected Version(s)

hydra >= 1.3.4, < 1.3.6 < 1.3.4, 1.3.6

hydra >= 1.4.0.dev0, < 1.4.0.dev9 < 1.4.0.dev0, 1.4.0.dev9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.