CVE-2026-48036
HIGHHulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
Title source: cnaDescription
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-32g3-35g9-wc9g
X_Refsource_Misc x_refsource_misc
https://github.com/kerberosmansour/hulumi/pull/178
X_Refsource_Misc x_refsource_misc
https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0
Scores
CVSS v4
8.4
EPSS
0.0029
EPSS Percentile
21.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-755
Status
published
Products (1)
kerberosmansour/hulumi
< 1.4.0
Published
Jul 24, 2026
Tracked Since
Jul 25, 2026