PT-2026-83733 · Npm · @Hulumi/Policies

·

CVE-2026-82856

·

Published

2026-05-21

·

Updated

2026-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @hulumi/policies versions prior to 1.3.2
Description Failure to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies allows attackers to bypass security guardrails. Specifically, the G OIDC 1 check only evaluated exact AWS IAM StringLike and StringEquals condition operator keys, failing to account for set-qualified operators such as ForAnyValue:StringLike. This oversight enables the use of wildcard GitHub Actions OIDC subject conditions that should be restricted.
Recommendations Upgrade @hulumi/policies to version 1.3.2 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82856
GHSA-Q2F7-M237-V562

Affected Products

@Hulumi/Policies