PT-2026-107114 · Hydra · Hydra

CVE-2026-106442

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hydra versions 1.3.4 through 1.3.5 Hydra versions 1.4.0.dev1 through 1.4.0.dev8
Description The instantiate() function contains a flaw where the target blacklist incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization through pickle.loads, aliases, callable-returning helpers, generic dispatch, and deferred calls can obscure the effective target and bypass name-based authorization. An attacker who can cause an application to instantiate untrusted configuration can use these gaps to execute arbitrary code with the application's privileges.
Recommendations Update to version 1.3.6. Update to version 1.4.0.dev9.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106442
GHSA-RQX7-P7VV-W7HR

Affected Products

Hydra