๐Ÿ” CVE Alert

CVE-2026-48034

UNKNOWN 0.0

HULUMI-H5 bypass via decoy sibling resources targeting a different bucket

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0.

CWE CWE-284
Vendor kerberosmansour
Product hulumi
Published Jul 24, 2026
Last Updated Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for kerberosmansour hulumi

Be the first to know when new unknown vulnerabilities affecting kerberosmansour hulumi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kerberosmansour / hulumi
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-9vc9-4jv3-rf86 github.com: https://github.com/kerberosmansour/hulumi/pull/175 github.com: https://github.com/kerberosmansour/hulumi/pull/178 github.com: https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0