A vulnerability in the hydra-optuna-sweeper package allows for the execution of untrusted callables via the get_method API. This issue arises from the package's acceptance of a configuration-controlled dotted path in hydra.sweeper.custom_search_space, which is resolved and invoked without applying the execution policy used by instantiate() and logging configuration. As a result, an attacker could potentia [truncated]
A vulnerability in Hydra's legacy `instantiate()` target blocklists allows for target blocklist bypass due to mutable module-level state. This affects `hydra-core` versions 1.3.4 through 1.3.6 and 1.4.0.dev4 through 1.4.0.dev9. Fixed releases are 1.3.7 and 1.4.0.dev10. The vulnerability arises from the legacy `instantiate()` target blocklists being stored in mutable module-level state, allowing a configur [truncated]
Hydra logging configuration permits unsafe callable resolution, allowing attackers to execute code with application privileges when configuring logging. This vulnerability affects Hydra's logging configuration, which was not properly mediated by the target policy, allowing for the execution of arbitrary code. Defenders should assess exposure and prioritize remediation, especially in environments where log [truncated]
CVE-2026-106442 is a vulnerability in Hydra's `instantiate()` API that allows for code execution with the application's privileges when an untrusted Hydra configuration is instantiated. The target blacklist introduced for CVE-2026-68508 was incomplete, allowing bypasses through execution wrappers, executable deserialization, and generic dispatch or wrapper targets. Hydra 1.3.6 and 1.4.0.dev9 have addresse [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:02.963Z and has not been modified since then. The Hydra framework versions prior to 1.3.4 are vulnerable to arbitrary code execution due to the insecure use of hydra.utils.instantiate(). This function allows attacker-controlled target values and arguments to choose dangerous callables, enab [truncated]