CVE-2026-48036
Received Received - Intake

Drift Detection False Positives in Hulumi Toolkit

Vulnerability report for CVE-2026-48036, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: GitHub, Inc.

Description

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" β€” masking real attacks for up to six hours β€” or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-25
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hulumi hulumi to 1.4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-755 The product does not handle or incorrectly handles an exceptional condition.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Hulumi before version 1.4.0 causes drift detection in CI or cron jobs to incorrectly cache transient adapter failures as successful checks. This masks real security issues for up to six hours or mislabels normal provider updates as critical incidents, making the security verdict unreliable for automated incident response workflows.

Detection Guidance

Detection requires checking the installed version of Hulumi. If you are running a version prior to 1.4.0, the vulnerability is present. Use commands like 'hulumi version' or check your package manager for installed versions.

Impact Analysis

You could miss actual security breaches because failures are cached as 'all clear', or waste resources responding to false alarms from normal provider changes. This affects incident response reliability and may delay detection of real threats.

Compliance Impact

The vulnerability could lead to unreliable security incident detection, potentially causing undetected breaches or false alerts. This may impact compliance by failing to meet requirements for timely breach detection and response under standards like GDPR (72-hour reporting) or HIPAA (security incident monitoring).

Mitigation Strategies

Upgrade Hulumi to version 1.4.0 or later immediately. This version includes the patch for the drift detection issue. Verify the upgrade with version check commands after installation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48036. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart