CVE-2026-48036

high

Description

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.

References

https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-32g3-35g9-wc9g

https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0

https://github.com/kerberosmansour/hulumi/pull/178

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48726

Details

Source: Mitre, NVD

Published: 2026-07-24

Updated: 2026-07-28

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

CVSS v4

Base Score: 8.4

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L

Severity: High

EPSS

EPSS: 0.0004