HIGH7.5
PYSEC-2026-1208
Azure Core is vulnerable to deserialization of untrusted data
Quick fix
PYSEC-2026-1208 — azure-core: upgrade to the fixed version with the command below.
pip install --upgrade 'azure-core>=1.38.0'Details
Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-21226[ADVISORY]
- https://github.com/Azure/azure-sdk-for-python[PACKAGE]
- https://github.com/Azure/azure-sdk-for-python/blob/6d2e6431ea0991861640e449e51e894247a7771a/sdk/core/azure-core/CHANGELOG.md#1380-2026-01-12[WEB]
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21226[WEB]
- https://pypi.org/project/azure-core[PACKAGE]
- https://github.com/advisories/GHSA-jm66-cg57-jjv5[ADVISORY]