CVE-2026-82855
Evidence validation bypass in @hulumi/policies Cloudflare and deployment validators
The @hulumi/policies package before version 1.3.2 contains an evidence validation bypass (CWE-693, protection mechanism failure) in its Cloudflare and deployment-governance validators, which fail to confirm that submitted compliance evidence belongs to the resource being checked. An attacker triggers the flaw by submitting compliant evidence taken from a different zone, hostname, origin, or repository than the resource under evaluation within the same stack. As a result, policy violations can be suppressed and security guardrails for unrelated resources in the same stack can be bypassed, letting non-compliant deployments pass governance checks. Any team running @hulumi/policies versions before 1.3.2 in automated policy-enforcement or deployment pipelines is affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.
What to do: Upgrade @hulumi/policies to version 1.3.2 or later, which corrects the evidence-matching checks in the Cloudflare and deployment-governance validators. Until upgraded, manually review recent policy approvals to confirm that submitted evidence actually corresponds to the zone, hostname, origin, or repository it certifies, and treat automated 'compliant' results from older versions as unverified.
| hulumi @hulumi/policies | all versions before 1.3.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers can use evidence from different zones, hostnames, origins, or repositories to bypass security guardrails for unrelated resources in the same stack.
- Weakness
- CWE-693
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.