dependency-check / dependency-check/DependencyCheck
[FP]: CVE-2026-33117 reported against unrelated Azure libraries
- Dominant language
- Java
- Stars
- 7.7k
- Forks
- 1.4k
- Avg merge
- 9d 22h
- Merged PRs (30d)
- 13
Description
### Package URl
pkg:maven/com.microsoft.azure/azure-data-lake-store-sdk@2.3.9
### CPE
cpe:2.3:a:microsoft:azure_sdk_for_java:2.3.9:*:*:*:*:*:*:*
### CVE
CVE-2026-33117
### ODC Integration
{"label" => "Maven Plugin"}
### ODC Version
12.2.2
### Description
On [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-33117)'s CPE is targeting `azure_sdk_for_java`, so matching `azure-data-lake-store-sdk` seems to be a false positive to me.
This also affects `pkg:maven/com.microsoft.azure/azure-keyvault-core@1.0.0`, and I would therefore _assume_ [any Azure client library](https://azure.github.io/azure-sdk/releases/latest/java.html).
Of note - I _also_ think the NVD CPE may be too broad - the [Microsoft docs](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117) suggests the problem/fix is in the `com.azure:azure-security-keyvault-keys` library. I will flag to NVD.
Contributor guide
Assessment
This issue has not been assessed yet.