Answer in brief
CVE-2026-106440 records a High severity (CVSS 7.8) vulnerability in Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_method. The current sources do not mark it as known exploited. The current feed maps hydra-ecosystem/hydra (generic), hydra-optuna-sweeper (pip), hydra-optuna-sweeper (pip). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps hydra-ecosystem/hydra (generic), hydra-optuna-sweeper (pip), hydra-optuna-sweeper (pip). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| hydra-ecosystem/hydrageneric | >=1.2.0 <1.3.0 || >=1.4.0.dev4 <1.4.0.dev10 | 1.3.0, 1.4.0.dev10 |
| hydra-optuna-sweeperpip | >=1.2.0,<1.3.0 | 1.3.0 |
| hydra-optuna-sweeperpip | >=1.4.0.dev4,<1.4.0.dev10 | 1.4.0.dev10 |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hydra.utils.get_method(), and later invokes the returned callable in the Hydra controller process. Because get_method() is a trusted-input lookup helper and does not apply the execution policy used by instantiate(), an attacker who controls Optuna sweep configuration or command-line overrides can select importable Python code for execution with the application's privileges, including bypassing a trusted execution whitelist on affected Hydra 1.4 development releases. This issue is fixed in versions 1.3.0 and 1.4.0.dev10.
Quoted source text, attributed separately from HOL analysis.