Security: kerberosmansour/hulumi
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub postureGHSA-cj8g-prcm-mfg5 published
May 20, 2026 by kerberosmansourModerate -
Drift classifier fails open on adapter errors and over-promotes Mixed verdictsGHSA-32g3-35g9-wc9g published
May 20, 2026 by kerberosmansourModerate -
AccountFoundation audit-delivery S3 bucket could be silently weakenedGHSA-2mxr-p26x-mj73 published
May 20, 2026 by kerberosmansourHigh -
HULUMI-H5 bypass via decoy sibling resources targeting a different bucketGHSA-9vc9-4jv3-rf86 published
May 20, 2026 by kerberosmansourHigh -
Policy packs bypassed by a forged Pulumi-URN logical nameGHSA-rhgj-6g2c-frmm published
May 20, 2026 by kerberosmansourHigh -
IAM-role policy checks bypassed when the role trusts multiple OIDC providersGHSA-g759-4pxw-6692 published
May 20, 2026 by kerberosmansourHigh -
Stack-wide evidence bypassed Cloudflare and deployment-governance guardrailsGHSA-59f3-7227-wmh4 published
May 15, 2026 by kerberosmansourHigh -
GitHub OIDC trust policy bypass via AWS set-qualified condition operatorsGHSA-q2f7-m237-v562 published
May 15, 2026 by kerberosmansourHigh -
Weekly integration IAM policy enabled role privilege escalationGHSA-35qr-vx94-m5x3 published
May 15, 2026 by kerberosmansourHigh -
Orphan reconciler accepted externally supplied execute plansGHSA-2ffm-hxrq-qqmm published
May 15, 2026 by kerberosmansourHigh