VulnSea

hydra vulnerabilities

CVEs whose affected-version data names the hydra package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-106439High· 8.5PoC
yesterday

Hydra is a framework for elegantly configuring complex applications

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An att…

▾ Midnighthydra-ecosystem · hydravia NVD
CVE-2026-106440High· 7.8
yesterday

Hydra is a framework for elegantly configuring complex applications

Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves i…

▾ Twilighthydra-ecosystem · hydravia NVD
CVE-2026-106441High· 7.8
yesterday

Hydra is a framework for elegantly configuring complex applications

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values o…

▾ Twilighthydra-ecosystem · hydravia NVD
CVE-2026-106442High· 7.8
yesterday

Hydra is a framework for elegantly configuring complex applications

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the targe…

▾ Twilighthydra-ecosystem · hydravia NVD
hydra vulnerabilities (CVEs) · VulnSea