High severityNVD Advisory· Published Jul 24, 2026· Updated Jul 28, 2026
CVE-2026-48036
CVE-2026-48036
Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@hulumi/driftnpm | < 1.4.0 | 1.4.0 |
Affected products
1- Range: <1.4.0
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.