CVE-2026-48036 Details
Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.
A vulnerability exists in the Hulumi open-source toolkit, specifically in the drift detection component, prior to version 1.4.0. The issue arises from the drift classifier's failure to properly handle errors from its adapters, which can lead to incorrect caching of verdicts. This flaw can mask real attacks for up to six hours or falsely escalate normal provider-version changes to incident severity. As a result, the reliability of the verdict source for downstream incident workflows is compromised.
Users can upgrade to Hulumi version 1.4.0 to address this vulnerability. This version includes a fix that ensures adapter failures are properly handled and do not degrade the verdict to 'None / none', which was previously cached for six hours. Instructions for downloading the latest version are available on the Hulumi GitHub Releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kerberosmansour/hulumi/pull/178 | [email protected] | Source CodeVendor |
| https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0 | [email protected] | Release NotesVendor |
| https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-32g3-35g9-wc9g | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-755 | Improper Handling of Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Hulumi | < 1.4.0 (semver) |
CPE
Remediation
| |
| Hulumi Drift | < 1.4.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 25, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | New CVE Received | [email protected] |
Volerion