PULSE
FEED
ransompanzer reclama a SweetRush · US · Professional Servicesransomincransom reclama a magnals.com · US · Otherransomdeadlock reclama a Greggio Argento · IT · Agriculture and Food Productionransomeverest reclama a Agri Industrial · Agriculture and Food Productionransomeverest reclama a B-accountants · NL · Professional Servicesransomeverest reclama a Morcon Developments · Otherransomeverest reclama a Kennametal · US · Manufacturingransomeverest reclama a Flydubai · AE · Transportationransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransompanzer reclama a SweetRush · US · Professional Servicesransomincransom reclama a magnals.com · US · Otherransomdeadlock reclama a Greggio Argento · IT · Agriculture and Food Productionransomeverest reclama a Agri Industrial · Agriculture and Food Productionransomeverest reclama a B-accountants · NL · Professional Servicesransomeverest reclama a Morcon Developments · Otherransomeverest reclama a Kennametal · US · Manufacturingransomeverest reclama a Flydubai · AE · Transportationransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Services
← Todos los CVEs
CVE Watch6 oct 2026

CVE-2026-106439

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate

CVSS

—

Sin CVSS

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 6 oct 2026 · Última mod.: 6 oct 2026 · CWE-470 · CWE-693

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An attacker who controls multiple sibling target entries can resolve hydra._internal.target_policy.UNCONTROLLED_EXECUTION_TARGETS.discard through instantiate(), remove a denied target, and then invoke that target because sibling nodes are processed in insertion order against the same modified policy. The mutation persists in process-global state and can enable code execution with the application's privileges, while a narrow execution whitelist supplied by trusted Python code is not bypassed by the reported direct mutation path. This issue is fixed in versions 1.3.7 and 1.4.0.dev10.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1064407.8 ALT
—
———Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hydra.utils.get_method(), and later invokes the returned callable in the Hydra controller process. Because get_method() is a trusted-input lookup helper and does not apply the execution policy used by instantiate(), an attacker who controls Optuna sweep configuration or command-line overrides can select importable Python code for execution with the application's privileges, including bypassing a trusted execution whitelist on affected Hydra 1.4 development releases. This issue is fixed in versions 1.3.0 and 1.4.0.dev10.3h
CVE-2026-106408—
—
———Protection mechanism failure in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)3h
CVE-2026-1057827.5 ALT
—
——0Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path as a referrer policy class, imported the referenced object, and called it. A malicious website could supply a callable such as sys.exit and terminate a crawler processing the response. This issue is fixed in version 2.14.2.7h
CVE-2026-1057462.2 BAJ
—
——0Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.83.0 until 2.131.0, the KServeV2OcrModel class defined in docling/models/stages/ocr/kserve_v2_ocr_model.py sends page images to its configured endpoint without checking the pipeline_options.enable_remote_services setting, even when the caller sets that policy control to false. The StandardPdfPipeline._make_ocr_model method also fails to pass the flag into the OCR factory, allowing remote OCR processing in configurations that rely on remote services being disabled. The destination is configured by the caller rather than selected by an attacker. This issue is fixed in 2.131.0.6h
CVE-2026-1050646.5 MED
13.3%
——4Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.22.8h
CVE-2017-202859.1 CRÍ
7.2%
——2YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.6h
CVE-2026-106439 — Hydra is a framework for elegantly configuring complex applications. From 1.3.4 · Pulse | Pulse