Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.24% | — | Hulumi BaselineAI | 31/8/2026 | 31/8/2026 | @hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring. | |
| Aplazada | Alta (8.6) | 0.19% | — | HulumiAI | 31/8/2026 | 1/9/2026 | Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution. | |
| Aplazada | Alta (8.7) | 0.43% | — | Hulumi PoliciesAI | 31/8/2026 | 2/9/2026 | @hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations. | |
| Aplazada | Crítica (9.3) | 0.54% | — | Hulumi PoliciesAI | 31/8/2026 | 31/8/2026 | @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls. | |
| Aplazada | Crítica (9.3) | 0.54% | — | HulumiAI | 31/8/2026 | 10/9/2026 | hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Hulumi DriftAI | 31/8/2026 | 31/8/2026 | @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations. | |
| Aplazada | Crítica (9.3) | 0.51% | — | HulumiAI | 31/8/2026 | 1/9/2026 | hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account. | |
| Aplazada | Crítica (9.3) | 0.51% | — | Hulumi PoliciesAIGithub ActionsAI | 31/8/2026 | 2/9/2026 | @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject conditions from security guardrails. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Hulumi PoliciesAI | 31/8/2026 | 31/8/2026 | @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers can use evidence from different zones, hostnames, origins, or repositories to… | |
| Aplazada | Media (6.3) | 0.45% | — | Pulumi HulumiAI | 24/7/2026 | 28/7/2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0. | |
| Aplazada | Alta (7.1) | 0.45% | — | Pulumi HulumiAIAmazon AWSAI | 24/7/2026 | 30/7/2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the… | |
| Aplazada | Alta (8.5) | 0.45% | — | Pulumi HulumiAI | 24/7/2026 | 28/7/2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0. | |
| Aplazada | Alta (8.4) | 0.48% | — | Pulumi HulumiAI | 24/7/2026 | 28/7/2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0. |