Back to vendor advisories
Microsoft Security Response CenterCVE-2026-33117

Azure SDK for Java Security Feature Bypass Vulnerability

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.

9.1CVSS out of 10High severity
Scope

What the vendor says is affected

  • Azure SDK for Java

Versions the vendor lists as fixed

  • 4.10.6
Next step

What the vendor recommends

Release Notes

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Updated by Microsoft Security Response Center

    The vendor changed the advisory after it was first published.

  3. Added to SecurityAlert

    We collected the advisory from the official source.

Vulnerabilities

CVEs named in this advisory