CVE-2026-82858

Source
https://cve.org/CVERecord?id=CVE-2026-82858
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82858.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82858
Aliases
Published
2026-08-31T08:46:31Z
Modified
2026-09-02T03:47:23Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
@hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance
Details

@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-345"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82858.json"
}
References

Affected packages

Git / github.com/kerberosmansour/hulumi

Affected ranges

Type
GIT
Repo
https://github.com/kerberosmansour/hulumi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.3.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v1.*
v1.2.0
v1.3.0
v1.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82858.json"