ZeroHour

CVE-2026-82858

Provenance validation flaw in @hulumi/drift allows untrusted execute plans

CVSS 4.0
9.3 critical
EPSS
<1%p9
Published
()
Modified
AI analysis

@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, an insufficient data-authenticity flaw (CWE-345) that causes untrusted reconciliation input to be treated as trusted. An attacker who can feed a crafted execute plan into a drift run over the network can trigger the flaw without privileges or user interaction, consistent with the critical CVSS 4.0 score of 9.3. Because the malicious plan bypasses security checks, the attacker can perform unsafe reconciliation operations with high impact to the confidentiality, integrity, and availability of the affected system, though per the CVSS scoring the impact does not extend to other systems. Anyone running @hulumi/drift prior to 1.3.2 is affected, particularly deployments that ingest execute plans from external or untrusted sources. There is no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates roughly a 0.2% probability of exploitation within 30 days.

What to do: Upgrade @hulumi/drift to version 1.3.2 or later, the first version not affected per the advisory. Until upgraded, restrict execute-plan ingestion to trusted, verified sources, validate plan provenance (e.g., source allowlisting or signatures) before processing, and review recent reconciliation runs for plans that originated from untrusted inputs.

Affected
Hulumi @hulumi/driftall versions before 1.3.2
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.

Weakness
CWE-345
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.