Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0.
Published: 2026-07-24
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Hulumi is an open‑source toolkit that ships secure‑by‑default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, a bypass exists that allows decoy sibling resources to target a bucket other than the one intended, potentially leading to unintended bucket access. The issue was addressed in release 1.4.0.

Affected Systems

The open‑source Hulumi collection developed by Kerberosmansour. Versions prior to 1.4.0 contain the vulnerability; the issue was fixed in release 1.4.0 and later.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity risk, while the EPSS score of less than 1% shows a low but non‑zero likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker who can influence Pulumi deployment scripts or configurations can add decoy sibling resources targeting a different bucket, thereby exploiting the unrestricted access rights in older Hulumi versions.

Generated by OpenCVE AI on August 3, 2026 at 19:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Hulumi v1.4.0 or later, which contains the fix for the sibling resource bypass.
  • Remove any decoy sibling resources that reference buckets other than the intended target.
  • Apply strict bucket policies and enforce cross‑bucket access controls at the cloud provider level to prevent accidental cross‑bucket operations.

Generated by OpenCVE AI on August 3, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9vc9-4jv3-rf86 @hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Kerberosmansour
Kerberosmansour hulumi
Vendors & Products Kerberosmansour
Kerberosmansour hulumi

Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0.
Title HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L'}


Subscriptions

Kerberosmansour Hulumi
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-24T20:15:32.345Z

Reserved: 2026-05-20T18:15:53.577Z

Link: CVE-2026-48034

cve-icon Vulnrichment

Updated: 2026-07-24T20:15:14.209Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T19:16:58.477

Modified: 2026-07-28T16:17:16.127

Link: CVE-2026-48034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:00:12Z

Weaknesses