PT-2026-83735 · Npm · @Hulumi/Drift

CVE-2026-82858

·

Published

2026-05-21

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @hulumi/drift versions prior to 1.3.2
Description Insufficient provenance validation allows the software to accept externally supplied execute plans, causing untrusted reconciliation input to be treated as trusted. This allows attackers to provide malicious execute plans that bypass security checks to perform unsafe reconciliation operations.
Recommendations Upgrade @hulumi/drift to version 1.3.2 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82858
GHSA-2FFM-HXRQ-QQMM

Affected Products

@Hulumi/Drift