Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jm66-cg57-jjv5 | Azure Core is vulnerable to deserialization of untrusted data |
Thu, 05 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft azure Core Shared Client Library
|
|
| CPEs | cpe:2.3:a:microsoft:azure_core_shared_client_library:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Microsoft azure Sdk For Python
|
Microsoft azure Core Shared Client Library
|
Tue, 20 Jan 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft azure Sdk For Python
|
|
| CPEs | cpe:2.3:a:microsoft:azure_sdk_for_python:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft azure Sdk For Python
|
Tue, 13 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. | |
| Title | Azure Core shared client library for Python Remote Code Execution Vulnerability | |
| First Time appeared |
Microsoft
Microsoft azure Core Shared Client Library For Python |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:microsoft:azure_core_shared_client_library_for_python:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft azure Core Shared Client Library For Python |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-04-01T13:49:21.414Z
Reserved: 2025-12-11T21:02:05.732Z
Link: CVE-2026-21226
Updated: 2026-01-13T18:28:29.233Z
Status : Analyzed
Published: 2026-01-13T19:16:23.987
Modified: 2026-02-05T17:58:29.607
Link: CVE-2026-21226
No data.
OpenCVE Enrichment
Updated: 2026-04-16T18:15:43Z
Github GHSA