Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 15 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:azure_container_apps:-:*:*:*:*:*:*:* |
Fri, 19 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. | |
| Title | Azure Container Apps Remote Code Execution Vulnerability | |
| First Time appeared |
Microsoft
Microsoft azure Container Apps |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:microsoft:azure_container_apps:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft azure Container Apps |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-04-16T14:19:05.350Z
Reserved: 2025-11-13T16:18:07.466Z
Link: CVE-2025-65037
Updated: 2025-12-19T15:10:37.271Z
Status : Analyzed
Published: 2025-12-18T22:16:01.433
Modified: 2026-01-15T21:55:28.097
Link: CVE-2025-65037
No data.
OpenCVE Enrichment
Updated: 2026-04-20T15:45:10Z