CVE Explorer
CVE-2026-48036
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been pa
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"hulumi","vendor":"kerberosmansour","versions":[{"status":"affected","version":"< 1.4.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:aae42fc1a82dd1b84a56df16894b2571a65d74902ae0c124f985fb4a6a32cc26 · sha256:3c1aadd6e6fb5a7f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.4,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"HIGH","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:aae42fc1a82dd1b84a56df16894b2571a65d74902ae0c124f985fb4a6a32cc26 · sha256:3c1aadd6e6fb5a7f… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-755","description":"CWE-755: Improper Handling of Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:aae42fc1a82dd1b84a56df16894b2571a65d74902ae0c124f985fb4a6a32cc26 · sha256:3c1aadd6e6fb5a7f… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/kerberosmansour/hulumi/pull/178","tags":["x_refsource_MISC"],"url":"https://github.com/kerberosmansour/hulumi/pull/178"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aae42fc1a82dd1b84a56df16894b2571a65d74902ae0c124f985fb4a6a32cc26 · sha256:3c1aadd6e6fb5a7f… · /containers/cna/references/1
{"name":"https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0","tags":["x_refsource_MISC"],"url":"https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aae42fc1a82dd1b84a56df16894b2571a65d74902ae0c124f985fb4a6a32cc26 · sha256:3c1aadd6e6fb5a7f… · /containers/cna/references/2
{"name":"https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-32g3-35g9-wc9g","tags":["x_refsource_CONFIRM"],"url":"https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-32g3-35g9-wc9g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aae42fc1a82dd1b84a56df16894b2571a65d74902ae0c124f985fb4a6a32cc26 · sha256:3c1aadd6e6fb5a7f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.