Back to overview

CVE-2026-48036

HIGH
8.4
CVSS 4.0
Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.

Metadata

CVE ID
CVE-2026-48036
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-05-20 18:15 UTC
Published
2026-07-24 18:44 UTC
Last updated
2026-07-25 00:58 UTC
Primary CWE
CWE-755
CWE-755: Improper Handling of Exceptional Conditions
Vendor / Product
kerberosmansour / hulumi
Sources
cve.org  ·  NVD

Severity & Metrics

8.4 HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
kerberosmansour hulumi < 1.4.0
Weakness (CWE)
CWESourceDescription
CWE-755 cna CWE-755: Improper Handling of Exceptional Conditions
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.4 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L
References (3)
Back to overview