CVE-2026-82858
—Provenance validation flaw in @hulumi/drift allows untrusted execute plans
@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, an insufficient data-authenticity flaw (CWE-345) that causes untrusted reconciliation input to be treated as trusted. An attacker who can feed a crafted execute plan into a drift run over the network can trigger the flaw without privileges or user interaction, consistent with the critical CVSS 4.0 score of 9.3. Because the malicious plan bypasses security checks, the attacker can perform unsafe reconciliation operations with high impact to the confidentiality, integrity, and availability of the affected system, though per the CVSS scoring the impact does not extend to other systems. Anyone running @hulumi/drift prior to 1.3.2 is affected, particularly deployments that ingest execute plans from external or untrusted sources. There is no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates roughly a 0.2% probability of exploitation within 30 days.
What to do: Upgrade @hulumi/drift to version 1.3.2 or later, the first version not affected per the advisory. Until upgraded, restrict execute-plan ingestion to trusted, verified sources, validate plan provenance (e.g., source allowlisting or signatures) before processing, and review recent reconciliation runs for plans that originated from untrusted inputs.
| Hulumi @hulumi/drift | all versions before 1.3.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.
- Weakness
- CWE-345
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.