CVE-2026-48037

Summary

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0.

Affected Software

VendorProductVersion RangeStatus
kerberosmansourhulumi< 1.4.0affected

Weaknesses

  • CWE-693: CWE-693: Protection Mechanism Failure

References