CVE-2026-48034 – HULUMI-H5 bypass via decoy sibling resources targeting a different bucket

​CVE ID :CVE-2026-48034

Published : July 24, 2026, 7:16 p.m. | 47 minutes ago

Description :Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0.

Severity: 8.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More