PkgRadar

PyPI · pypi.org

py-hydra

Py Runtime Pickle Loads: pickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled.

Why PkgRadar flagged 1.0.7

SeveritySignalEvidence
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · py_hydra-1.0.7/src/hydra/distributed_queues/joinable_queue.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.0Low risk02026-06-03
1.0.17Low risk02026-05-28
1.0.16Low risk02026-05-27
1.0.15Low risk02026-05-27
1.0.14Low risk02026-05-27
1.0.13Low risk02026-05-27
1.0.12Low risk02026-05-27
1.0.11Low risk02026-05-27
1.0.10Low risk02026-05-26
1.0.9Low risk02026-05-26
1.0.8Low risk02026-05-26
1.0.7Review202026-05-26
1.0.6Review202026-05-26
1.0.5Review202026-05-26
1.0.4Review202026-05-26

Block this in CI

PkgRadar gates py-hydra (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi py-hydra==1.0.7