Critical Evidence Validation Bypass in @hulumi/policies npm Package
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- @hulumi/policies (npm)
- Affected versions
- < 1.3.2 or < 1.3.2 or < 1.4.0 or < 1.3.2 or < 1.4.0 or < 1.3.2 or < 1.4.0
- Patched version
- 1.3.2
The @hulumi/policies npm package versions before 1.3.2 contain a critical evidence validation bypass vulnerability. This vulnerability allows attackers to suppress violations by submitting unrelated compliant evidence.
What happened
The @hulumi/policies npm package versions before 1.3.2 have been confirmed to contain a critical evidence validation bypass vulnerability. This vulnerability, tracked as CVE-2026-82855, affects Cloudflare and deployment-governance validators. Attackers can exploit this by submitting unrelated compliant evidence from different zones, hostnames, origins, or repositories to suppress violations. The vulnerability was first flagged on 2026-08-31T09:17:05.610000+00:00 and confirmed shortly after on 2026-08-31T10:12:11.385055+00:00.
To assess your exposure, check if your project dependencies include @hulumi/policies in a version before 1.3.2. If so, you are vulnerable to this critical CVE. The vulnerability has a CVSS score of 9.8, indicating a high severity level.
What to do about it
- Upgrade to @hulumi/policies@1.3.2 or later to mitigate the evidence validation bypass vulnerability.
- Review your project dependencies and ensure all instances of @hulumi/policies are updated to the patched version.
- Monitor the NVD and other primary sources for any updates or additional information related to this vulnerability.
How 0Day would have caught this
@hulumi/policies is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if your project dependencies include @hulumi/policies in a version before 1.3.2.
What should I do right now?
Upgrade to @hulumi/policies@1.3.2 or later to mitigate the vulnerability.
Has this been exploited in the wild?
No, this vulnerability has not been exploited in the wild according to the primary sources.