{"id":"GHSA-59f3-7227-wmh4","summary":"@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails","details":"Impact: @hulumi/policies versions before 1.3.2 used stack-wide evidence shortcuts in several Cloudflare and deployment-governance validators. Unrelated compliant-looking evidence could suppress violations for different zones, hostnames, origins, or repositories in the same stack.\n\nPatched in 1.3.2: validators now correlate evidence to the specific protected resource and include regression coverage for unrelated-evidence bypasses.\n\nRemediation: upgrade @hulumi/policies to 1.3.2 or later.","aliases":["CVE-2026-82855"],"modified":"2026-09-10T03:51:04.581683759Z","published":"2026-05-21T20:47:44Z","database_specific":{"github_reviewed_at":"2026-05-21T20:47:44Z","nvd_published_at":null,"cwe_ids":["CWE-693"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-59f3-7227-wmh4"},{"type":"PACKAGE","url":"https://github.com/kerberosmansour/hulumi"}],"affected":[{"package":{"name":"@hulumi/policies","ecosystem":"npm","purl":"pkg:npm/%40hulumi/policies"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-59f3-7227-wmh4/GHSA-59f3-7227-wmh4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}