PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106440 hydra-ecosystem CVE debrief

A vulnerability in the hydra-optuna-sweeper package allows for the execution of untrusted callables via the get_method API. This issue arises from the package's acceptance of a configuration-controlled dotted path in hydra.sweeper.custom_search_space, which is resolved and invoked without applying the execution policy used by instantiate() and logging configuration. As a result, an attacker could potentially execute installed Python code in the Hydra controller process with the privileges of the application.

Vendor
hydra-ecosystem
Product
hydra-optuna-sweeper
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Hydra applications using the hydra-optuna-sweeper package should assess their exposure and verify the trustworthiness of their Optuna sweep configurations and command-line overrides.

Why it matters

This vulnerability allows for the execution of untrusted code in the Hydra controller process, potentially leading to arbitrary code execution with application privileges. Defenders should verify Optuna sweep configurations, review importable callables, and apply fixes to prevent exploitation.

  • Execution of arbitrary code with application privileges
  • Potential bypass of execution whitelist in Hydra 1.4 development releases
  • Restoration of legacy blocklist as defense in depth in Hydra 1.3

Technical summary

The hydra-optuna-sweeper package is vulnerable to the execution of untrusted callables via the get_method API. This occurs because the package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it, and then invokes the returned callable without applying the execution policy used by instantiate() and logging configuration. The vulnerability allows for the execution of installed Python code in the Hydra controller process with the privileges of the application. Defenders should prioritize verifying the Optuna sweep configuration and command-line overrides, ensuring that only trusted code is executed. They should also review the application's environment for importable [

Defensive priority

Defenders should prioritize verifying the Optuna sweep configuration and command-line overrides, ensuring that only trusted code is executed. They should also review the application's environment for importable callables that could be exploited.

Recommended defensive actions

  • Verify Optuna sweep configuration and command-line overrides for trustworthiness
  • Review the application's environment for importable callables that could be exploited
  • Apply the fix by resolving the configured callback through hydra.utils.instantiate() as a partial callable
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is confirmed in Hydra 1.4 development releases and 1.3 versions prior to 1.3.7. The fix involves resolving the configured callback through hydra.utils.instantiate() as a partial callable.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106440 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106440

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106440 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106440

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_method

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-5jjj-9xc3-rm56.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/hydra-ecosystem/hydra/security/advisories/GHSA-5jjj-9xc3-rm56

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/hydra-ecosystem/hydra/commit/0dd18084589a3d3e577d1f1a8a48fb485c94a5e6

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/hydra-ecosystem/hydra/commit/4720dfca2bde27fa140ec287a05709668fbdf168

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/hydra-ecosystem/hydra

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/hydra-ecosystem/hydra/releases/tag/v1.3.7

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.