VYPR
Critical severity9.1NVD Advisory· Published May 12, 2026· Updated May 22, 2026

CVE-2026-33117

CVE-2026-33117

Description

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.azure:azure-security-keyvault-keysMaven
< 4.10.64.10.6

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

3