Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Splunk | — | Upgrade Splunk Enterprise to version 9.3.10Upgrade Splunk Enterprise to version 10.2.1Upgrade Splunk Enterprise to version 10.0.5Upgrade Splunk Enterprise to version 10.2.2Upgrade Splunk Enterprise to version 9.4.10Upgrade Splunk Enterprise to version 9.3.11Upgrade Splunk Enterprise to version 9.4.9Upgrade Splunk Enterprise to version 10.0.4 | Apr 10, 2026 | Jan 13, 2026 |
| Suse | — | Upgrade python311-azure-coreUpgrade python313-azure-core | Feb 13, 2026 | Feb 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub