PatchSiren cyber security CVE debrief
CVE-2026-106440 hydra-ecosystem CVE debrief
A vulnerability in the hydra-optuna-sweeper package allows for the execution of untrusted callables via the get_method API. This issue arises from the package's acceptance of a configuration-controlled dotted path in hydra.sweeper.custom_search_space, which is resolved and invoked without applying the execution policy used by instantiate() and logging configuration. As a result, an attacker could potentially execute installed Python code in the Hydra controller process with the privileges of the application.
- Vendor
- hydra-ecosystem
- Product
- hydra-optuna-sweeper
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Hydra applications using the hydra-optuna-sweeper package should assess their exposure and verify the trustworthiness of their Optuna sweep configurations and command-line overrides.
Why it matters
This vulnerability allows for the execution of untrusted code in the Hydra controller process, potentially leading to arbitrary code execution with application privileges. Defenders should verify Optuna sweep configurations, review importable callables, and apply fixes to prevent exploitation.
- Execution of arbitrary code with application privileges
- Potential bypass of execution whitelist in Hydra 1.4 development releases
- Restoration of legacy blocklist as defense in depth in Hydra 1.3
Technical summary
The hydra-optuna-sweeper package is vulnerable to the execution of untrusted callables via the get_method API. This occurs because the package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it, and then invokes the returned callable without applying the execution policy used by instantiate() and logging configuration. The vulnerability allows for the execution of installed Python code in the Hydra controller process with the privileges of the application. Defenders should prioritize verifying the Optuna sweep configuration and command-line overrides, ensuring that only trusted code is executed. They should also review the application's environment for importable [
Defensive priority
Defenders should prioritize verifying the Optuna sweep configuration and command-line overrides, ensuring that only trusted code is executed. They should also review the application's environment for importable callables that could be exploited.
Recommended defensive actions
- Verify Optuna sweep configuration and command-line overrides for trustworthiness
- Review the application's environment for importable callables that could be exploited
- Apply the fix by resolving the configured callback through hydra.utils.instantiate() as a partial callable
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is confirmed in Hydra 1.4 development releases and 1.3 versions prior to 1.3.7. The fix involves resolving the configured callback through hydra.utils.instantiate() as a partial callable.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106440 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106440
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106440 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106440
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_method
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-5jjj-9xc3-rm56.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/hydra-ecosystem/hydra/security/advisories/GHSA-5jjj-9xc3-rm56
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/hydra-ecosystem/hydra/commit/0dd18084589a3d3e577d1f1a8a48fb485c94a5e6
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/hydra-ecosystem/hydra/commit/4720dfca2bde27fa140ec287a05709668fbdf168
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/hydra-ecosystem/hydra
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/hydra-ecosystem/hydra/releases/tag/v1.3.7
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.