CVE-2026-106439High· 8.5▾ MidnightPoC availableHydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An att…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 46.8 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An attacker who controls multiple sibling target entries can resolve hydra._internal.target_policy.UNCONTROLLED_EXECUTION_TARGETS.discard through instantiate(), remove a denied target, and then invoke that target because sibling nodes are processed in insertion order against the same modified policy. The mutation persists in process-global state and can enable code execution with the application's privileges, while a narrow execution whitelist supplied by trusted Python code is not bypassed by the reported direct mutation path. This issue is fixed in versions 1.3.7 and 1.4.0.dev10.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106440High· 7.8Hydra is a framework for elegantly configuring complex applications
CVE-2026-106441High· 7.8Hydra is a framework for elegantly configuring complex applications
CVE-2026-106442High· 7.8Hydra is a framework for elegantly configuring complex applications
CVE-2026-76825High· 8.4RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment
CVE-2026-28757Medium· 6.7Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege
CVE-2026-24693Medium· 6.7Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User Applications may allow an escalation of privilege