Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jm66-cg57-jjv5 Azure Core is vulnerable to deserialization of untrusted data
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 13 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Jan 2026 18:30:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.
Title Azure Core shared client library for Python Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft azure Core Shared Client Library For Python
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:azure_core_shared_client_library_for_python:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Core Shared Client Library For Python
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-01-16T21:28:29.529Z

Reserved: 2025-12-11T21:02:05.732Z

Link: CVE-2026-21226

cve-icon Vulnrichment

Updated: 2026-01-13T18:28:29.233Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-13T19:16:23.987

Modified: 2026-01-14T16:25:40.430

Link: CVE-2026-21226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses