GHSA-c3wx-c55w-pxjq: Code Injection

Published Oct 7, 2026
·
Updated

Summary

Hydra passed its Python logging configuration to logging.config.dictConfig(). Python's logging configurator can resolve and invoke importable classes and factories named by configuration, including handler class values and formatter, filter, handler, queue, and listener () factories.

This logging path was not mediated by Hydra's target policy. In versions that already protected instantiate(), logging resolution bypassed those controls because it did not use instantiate().

An attacker who can control a Hydra logging configuration can use a custom class or factory to execute code with the application's privileges when Hydra configures logging.

Fix

Hydra now applies its target policy to callable resolution and invocation in Hydra-configured Python logging. It authorizes custom factories, handlers, formatters, filters, queues, listeners, aliases, discovery results, and callable results before they can be used.

Hydra 1.3.6 uses the hardened blacklist. The Hydra 1.3 blacklist is a best-effort, defense-in-depth measure. It is not a complete security boundary and does not make untrusted logging configuration safe.

Hydra 1.4.0.dev9 introduces the execution whitelist as the recommended primary boundary, with the blacklist retained as a deprecated compatibility fallback. When an execution whitelist is supplied, Hydra automatically permits targets used by its built-in logging configurations, while custom logging integrations must be explicitly authorized by trusted Python code. If no whitelist is supplied, Hydra warns and preserves legacy fallback behavior.

Remediation

Upgrade to Hydra 1.3.6, or to Hydra 1.4.0.dev9 or later when testing the 1.4 prerelease line.

On Hydra 1.3, do not compose logging configuration from untrusted sources. On Hydra 1.4 and later, constrain custom logging targets with a narrow execution whitelist supplied by trusted Python code. The execution whitelist controls callable selection; it is not general validation of all logging settings.

For Hydra 1.4 execution-whitelist configuration, see:

https://hydra.cc/docs/advanced/executionwhitelist/

Affected Software

2 affected componentsFixes available
pip/hydra-core>=1.4.0.dev0<1.4.0.dev9
1.4.0.dev9
pip/hydra-core<1.3.6
1.3.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/hydra-core to a version that resolves this vulnerability.

    Fixed in 1.4.0.dev9
  2. Upgrade

    Upgrade pip/hydra-core to a version that resolves this vulnerability.

    Fixed in 1.3.6
  3. Upgrade

    Upgrade Hydra 1.3 to a version that resolves this vulnerability.

    Fixed in 1.3.6
  4. Upgrade

    Upgrade Hydra 1.4 prerelease line to a version that resolves this vulnerability.

    Fixed in 1.4.0.dev9
  5. Configuration

    Constrain custom logging targets with a narrow execution whitelist supplied by trusted Python code.

    Hydra 1.4 and later execution whitelist = narrow whitelist supplied by trusted Python code
  6. Compensating control

    On Hydra 1.3, do not compose logging configuration from untrusted sources.

Event History

Oct 7, 2026
Advisory Published
via GitHub·06:03 PM
Data Sourced
via GitHub·06:03 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using Hydra are exposed if an attacker can control the Hydra logging configuration that is passed to Python's logging configurator. Exploitation runs code with the affected application's privileges.

2

What must an attacker control to exploit it?

The attacker needs control over a Hydra logging configuration. They can specify importable classes or callable factories through logging handler classes or formatter, filter, handler, queue, listener, and related factory configuration.

3

Are existing instantiate() protections sufficient?

No. The vulnerable logging path did not use instantiate(), so it bypassed target-policy controls that protected instantiate().

4

What versions contain the stated fixes?

Hydra 1.3.6 applies a hardened blacklist to logging callable resolution. Hydra 1.4.0.dev9 introduces an execution whitelist; the provided information does not state a final 1.4 release version.

5

Can Hydra 1.3 make untrusted logging configurations safe?

No. The Hydra 1.3 blacklist is described as best-effort defense in depth, not a complete security boundary. Untrusted logging configuration should not be treated as safe.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203