๐Ÿ” CVE Alert

CVE-2026-48033

UNKNOWN 0.0

Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.

CWE CWE-693
Vendor kerberosmansour
Product hulumi
Published Jul 24, 2026
Last Updated Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for kerberosmansour hulumi

Be the first to know when new unknown vulnerabilities affecting kerberosmansour hulumi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kerberosmansour / hulumi
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-rhgj-6g2c-frmm github.com: https://github.com/kerberosmansour/hulumi/pull/178 github.com: https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0