All 4 CVE vulnerabilities found in policies, with AI-generated Chinese analysis, references, and POCs.
Vendor: hulumi
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-82860 | @hulumi/policies before 1.3.2 Admin Policy Bypass CWE-269 | 9.8 | Critical | 2026-08-31 |
| CVE-2026-82861 | @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass CWE-284 | 7.5 | High | 2026-08-31 |
| CVE-2026-82856 | @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass CWE-284 | 9.8 | Critical | 2026-08-31 |
| CVE-2026-82855 | @hulumi/policies before 1.3.2 Evidence Validation Bypass CWE-693 | 9.8 | Critical | 2026-08-31 |
All 4 known CVE vulnerabilities affecting policies with full Chinese analysis, references, and POCs where available.