Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9vc9-4jv3-rf86 | @hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket |
Fri, 24 Jul 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0. | |
| Title | HULUMI-H5 bypass via decoy sibling resources targeting a different bucket | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-24T20:15:32.345Z
Reserved: 2026-05-20T18:15:53.577Z
Link: CVE-2026-48034
Updated: 2026-07-24T20:15:14.209Z
No data.
No data.
OpenCVE Enrichment
No data.
Github GHSA