CVE-2026-48036

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-24 19:16

Updated : 2026-07-28 16:17


NVD link : CVE-2026-48036

Mitre link : CVE-2026-48036

CVE.ORG link : CVE-2026-48036


JSON object : View

Products Affected

No product.

CWE
CWE-755

Improper Handling of Exceptional Conditions