Disclosure summary
## Summary Hydra's legacy `instantiate()` target blocklists and related execution-policy collections are stored in mutable module-level state. Because `_locate()` can resolve attributes on imported objects, a configuration can resolve a mutation method such as `.discard()`, modify the active policy, and then instantiate a target that would otherwise be blocked. ## Impact A configuration controlling multiple sibling `_target_` entries can first remove an entry from a target blocklist and then invoke the removed target. Sibling nodes are processed in insertion order and consult the same mutable module-level policy. This affects the legacy/default path without an execution whitelist. The 1.3 blocklist is a defense-in-depth measure rather than a complete security boundary, and applications must not treat arbitrary untrusted configuration as safe to instantiate or use for Python logging configuration. Released `hydra-core` versions 1.3.4 through 1.3.6 and 1.4.0.dev4 through 1.4.0.dev9 are affected. Fixed releases are 1.3.7 and 1.4.0.dev10. The reported direct mutation path does not bypass an execution whitelist restricted to intended application targets and supplied by trusted Python co
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-mwj6-rfh8-7qf4
Open original source · Updated Oct 07, 2026
Hydra: Mutable instantiate policy sets allow target blocklist bypass
Source severity: HIGH / 8.5
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | hydra-core | >= 1.3.4, < 1.3.7 | 1.3.7 |
| pip | hydra-core | >= 1.4.0.dev4, < 1.4.0.dev10 | 1.4.0.dev10 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T16:23:57-04:00
MODIFIED 2026-10-07T16:23:59-04:00
INGESTED 2026-10-08T12:30:39-04:00