Skip to content

[FP]: CVE-2026-33117 reported against unrelated Azure libraries #8553

@JackPGreen

Description

@JackPGreen

Package URl

pkg:maven/com.microsoft.azure/azure-data-lake-store-sdk@2.3.9

CPE

cpe:2.3:a:microsoft:azure_sdk_for_java:2.3.9:::::::*

CVE

CVE-2026-33117

ODC Integration

{"label" => "Maven Plugin"}

ODC Version

12.2.2

Description

On NVD's CPE is targeting azure_sdk_for_java, so matching azure-data-lake-store-sdk seems to be a false positive to me.

This also affects pkg:maven/com.microsoft.azure/azure-keyvault-core@1.0.0, and I would therefore assume any Azure client library.

Of note - I also think the NVD CPE may be too broad - the Microsoft docs suggests the problem/fix is in the com.azure:azure-security-keyvault-keys library. I will flag to NVD.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions