dependency-check / dependency-check/DependencyCheck

[FP]: CVE-2026-33117 reported against unrelated Azure libraries

Open
#8,553 2 comments 0 reactions 0 assignees View on GitHub
enhancement FP Report maven
Dominant language
Java
Stars
7.7k
Forks
1.4k
Avg merge
9d 22h
Merged PRs (30d)
13

Description

### Package URl

pkg:maven/com.microsoft.azure/azure-data-lake-store-sdk@2.3.9

### CPE

cpe:2.3:a:microsoft:azure_sdk_for_java:2.3.9:*:*:*:*:*:*:*

### CVE

CVE-2026-33117

### ODC Integration

{"label" => "Maven Plugin"}

### ODC Version

12.2.2

### Description

On [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-33117)'s CPE is targeting `azure_sdk_for_java`, so matching `azure-data-lake-store-sdk` seems to be a false positive to me.

This also affects `pkg:maven/com.microsoft.azure/azure-keyvault-core@1.0.0`, and I would therefore _assume_ [any Azure client library](https://azure.github.io/azure-sdk/releases/latest/java.html).

Of note - I _also_ think the NVD CPE may be too broad - the [Microsoft docs](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117) suggests the problem/fix is in the `com.azure:azure-security-keyvault-keys` library. I will flag to NVD.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.