CVE-2026-48036

Source
https://cve.org/CVERecord?id=CVE-2026-48036
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48036.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48036
Aliases
Published
2026-07-24T18:44:05.631Z
Modified
2026-08-12T03:51:21.003744437Z
Severity
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L CVSS Calculator
Summary
Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
Details

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48036.json",
    "cwe_ids": [
        "CWE-755"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/kerberosmansour/hulumi

Affected ranges

Type
GIT
Repo
https://github.com/kerberosmansour/hulumi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.4.0"
        }
    ]
}

Affected versions

v1.*
v1.2.0
v1.3.0
v1.3.1
v1.3.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48036.json"