๐Ÿ” CVE Alert

CVE-2026-48036

UNKNOWN 0.0

Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" โ€” masking real attacks for up to six hours โ€” or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.

CWE CWE-755
Vendor kerberosmansour
Product hulumi
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for kerberosmansour hulumi

Be the first to know when new unknown vulnerabilities affecting kerberosmansour hulumi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kerberosmansour / hulumi
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-32g3-35g9-wc9g github.com: https://github.com/kerberosmansour/hulumi/pull/178 github.com: https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0