hydra-ecosystem has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was October 2026 with 4. The median CVSS is 7.8 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-106439High· 8.5Hydra is a framework for elegantly configuring complex applications59CVE-2026-106442High· 7.8Hydra is a framework for elegantly configuring complex applications43CVE-2026-106441High· 7.8Hydra is a framework for elegantly configuring complex applications43CVE-2026-106440High· 7.8Hydra is a framework for elegantly configuring complex applications43
hydra-ecosystem vulnerabilities
CVEs affecting hydra-ecosystem, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-106439High· 8.5PoCHydra is a framework for elegantly configuring complex applications
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An att…
CVE-2026-106440High· 7.8Hydra is a framework for elegantly configuring complex applications
Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves i…
CVE-2026-106441High· 7.8Hydra is a framework for elegantly configuring complex applications
Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values o…
CVE-2026-106442High· 7.8Hydra is a framework for elegantly configuring complex applications
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the targe…