NONE · 0

CVE-2026-48036

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see ...

Vulnerability Description

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-48036?

CVE-2026-48036 is a documented vulnerability. Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see ...

How severe is CVE-2026-48036?

CVSS scoring is not yet available for CVE-2026-48036. Check NVD for updates.

Is there a patch for CVE-2026-48036?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.