๐Ÿ” CVE Alert

CVE-2026-48035

UNKNOWN 0.0

Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal โ€” while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.

CWE CWE-1059
Vendor kerberosmansour
Product hulumi
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for kerberosmansour hulumi

Be the first to know when new unknown vulnerabilities affecting kerberosmansour hulumi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kerberosmansour / hulumi
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-2mxr-p26x-mj73 github.com: https://github.com/kerberosmansour/hulumi/pull/178 github.com: https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0