---
id: CVE-2026-106441
title: Hydra is a framework for elegantly configuring complex applications
summary: >-
  Hydra is a framework for elegantly configuring complex applications. Prior to
  1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to
  logging.config.dictConfig() without applying Hydra's target policy to handler
  class values o…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: hydra-ecosystem
product: hydra
affected:
  - hydra < 1.3.6
  - 'hydra >= 1.4.0.dev0, < 1.4.0.dev9'
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:03:40.690'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106441'
references:
  - url: >-
      https://github.com/hydra-ecosystem/hydra/commit/76bfc30ce1f3105416941dd2e3a562568e369120
    label: security-advisories@github.com
  - url: >-
      https://github.com/hydra-ecosystem/hydra/commit/ff3e4dba890c29a21d8c2bb867ee87d37ccf21d0
    label: security-advisories@github.com
  - url: 'https://github.com/hydra-ecosystem/hydra/pull/3420'
    label: security-advisories@github.com
  - url: >-
      https://github.com/hydra-ecosystem/hydra/security/advisories/GHSA-c3wx-c55w-pxjq
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T19:13:33.852Z'
---

## Overview

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatter, filter, handler, queue, and listener factories. An attacker who controls Hydra logging configuration can therefore select an importable class or factory and cause it to be invoked with the application's privileges, even in versions where instantiate() is protected because the logging path does not use instantiate(). This issue is fixed in versions 1.3.6 and 1.4.0.dev9.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
