← Back to overview

CVE-2026-82855 affects @hulumi/policies versions before 1.3.2, exposing an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators. Attackers can exploit this flaw by submitting compliant evidence from unrelated zones, hostnames, origins, or repositories to suppress policy violations. This effectively allows bypassing security guardrails for unrelated resources within the same stack. The vulnerability resides in the validator logic that fails to properly correlate submitted evidence with the specific resource being validated. Organizations using this package for deployment governance or Cloudflare policy enforcement are at risk of having security controls silently bypassed. The fix is available in version 1.3.2 and above. The issue is tracked under GHSA-59f3-7227-wmh4 and documented by VulnCheck.

Affected products

  • '@hulumi/policies before 1.3.2

Related CVE's

  • CVE-2026-82855

Categories

  • Cloud & Virtualization
  • Supply Chain & Dependencies
  • Web Technologies