CVE-2026-48036

Published: Lug 24, 2026 Last Modified: Lug 25, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,4
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as 'all clear' — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.

755

Improper Handling of Exceptional Conditions

Incomplete
Common Consequences
Security Scopes Affected:
Other
Potential Impacts:
Other
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/kerberosmansour/hulumi/pull/178
https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0
https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-32g3-35g9-wc…