


Perceptive Security
SOC/SIEM Consultancy

@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attack…
Published:
31 augustus 2026 om 00:00:00
Alert date:
31 augustus 2026 om 12:05:42
Source:
nvd.nist.gov
Supply Chain & Dependencies, Cloud & Virtualization, Web Technologies
CVE-2026-82855 affects @hulumi/policies versions before 1.3.2, exposing an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators. Attackers can exploit this flaw by submitting compliant evidence from unrelated zones, hostnames, origins, or repositories to suppress policy violations. This allows bypassing security guardrails for unrelated resources within the same stack. The vulnerability undermines the integrity of policy enforcement mechanisms designed to govern deployments and Cloudflare configurations. The issue is resolved in version 1.3.2 of the package. The vulnerability has been assigned a high criticality rating, indicating significant risk to affected deployments. Organizations using @hulumi/policies for infrastructure governance should upgrade immediately to mitigate potential exploitation.
Technical details
Mitigation steps:
Affected products:
@hulumi/policies
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82855
https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-59f3-7227-wmh4
https://www.vulncheck.com/advisories/hulumi-policies-before-1.3.2-evidence-validation-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
