{"id":"CVE-2026-106439","summary":"Hydra: Mutable instantiate policy sets allow target blocklist bypass","details":"Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An attacker who controls multiple sibling target entries can resolve hydra._internal.target_policy.UNCONTROLLED_EXECUTION_TARGETS.discard through instantiate(), remove a denied target, and then invoke that target because sibling nodes are processed in insertion order against the same modified policy. The mutation persists in process-global state and can enable code execution with the application's privileges, while a narrow execution whitelist supplied by trusted Python code is not bypassed by the reported direct mutation path. This issue is fixed in versions 1.3.7 and 1.4.0.dev10.","aliases":["GHSA-mwj6-rfh8-7qf4"],"modified":"2026-10-07T10:45:39.990201975Z","published":"2026-10-06T18:49:12.110Z","database_specific":{"cwe_ids":["CWE-470","CWE-693"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106439.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.4.0.dev4"},{"fixed":"1.4.0.dev10"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106439.json"},{"type":"FIX","url":"https://github.com/hydra-ecosystem/hydra/commit/0dd18084589a3d3e577d1f1a8a48fb485c94a5e6"},{"type":"FIX","url":"https://github.com/hydra-ecosystem/hydra/commit/4720dfca2bde27fa140ec287a05709668fbdf168"},{"type":"WEB","url":"https://github.com/hydra-ecosystem/hydra/releases/tag/v1.3.7"},{"type":"ADVISORY","url":"https://github.com/hydra-ecosystem/hydra/security/advisories/GHSA-mwj6-rfh8-7qf4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106439"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hydra-ecosystem/hydra","events":[{"introduced":"81070c4266f2c7e0bb614f84585b3bd0cb721ce1"},{"fixed":"81715a5a258ae2657369344f4e3523e5fbabb2af"}],"database_specific":{"extracted_events":[{"introduced":"1.3.4"},{"fixed":"1.3.7"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.3.6","v1.3.5","v1.3.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106439.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}