Critical severity9.1NVD Advisory· Published May 12, 2026· Updated May 22, 2026
CVE-2026-33117
CVE-2026-33117
Description
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.azure:azure-security-keyvault-keysMaven | < 4.10.6 | 4.10.6 |
Affected products
3- Range: <4.10.6
- osv-coords2 versions
< 2.9.0-r9+ 1 more
- (no CPE)range: < 2.9.0-r9
- (no CPE)range: < 2.9.0-r9
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-97jf-46m3-8953ghsaADVISORY
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-33117ghsaADVISORY
- github.com/Azure/azure-sdk-for-java/commit/1b5c5c79d85a5c9a9cfd07f6cdff6fd0f50eccf9ghsaWEB
- github.com/Azure/azure-sdk-for-java/pull/48476ghsaWEB
News mentions
3- Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE FlawsThe Hacker News · May 13, 2026
- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026
- Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-daysBleepingComputer · May 12, 2026