Skip to content
SUSE Azure-Storage-AzCopy Faces Multiple Security Vulnerabilities

SUSE Azure-Storage-AzCopy Faces Multiple Security Vulnerabilities

First seen 19 Jun 2026, 23:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 20, 2026 at 22:49 UTC
  • SUSE released an important security update for azure-storage-azcopy on June 19, 2026.
  • Critical vulnerabilities include CVE-2026-33186 (CVSS 9.1) and CVE-2026-34986, which can lead to denial of service.
  • Administrators are advised to update to version 10.32.4 to address these vulnerabilities.

SUSE has released an important update for azure-storage-azcopy addressing several vulnerabilities. The update includes fixes for CVE-2025-47907, CVE-2026-33186, CVE-2026-33814, CVE-2026-34986, and CVE-2026-39821. Notably, CVE-2026-33186 has a CVSS score of 9.1, indicating a high severity due to an authorization bypass vulnerability. CVE-2026-34986 allows for denial of service through crafted JWE input. Other vulnerabilities involve improper validation and infinite loops that could lead to service disruptions. The update is critical for users of azure-storage-azcopy, particularly those relying on HTTP/2 transport. Administrators are urged to apply the update to mitigate potential risks. The vulnerabilities were disclosed between 2025 and 2026, with some having public proof-of-concept code available.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2025-08-07
CVE-2025-47907 published
A vulnerability in database/sql was disclosed, causing incorrect results from Rows.Scan.
Linuxsecurity
2026-03-20
CVE-2026-33186 published
An authorization bypass vulnerability due to improper validation of HTTP/2 path pseudo-header was disclosed.
Linuxsecurity
2026-04-06
CVE-2026-34986 published
A crafted JWE input vulnerability leading to denial of service was disclosed.
Linuxsecurity
2026-04-07
First public PoC for CVE-2026-33186
Proof-of-concept code for the authorization bypass vulnerability was made publicly available.
Linuxsecurity
2026-05-07
CVE-2026-33814 published
A vulnerability causing an infinite loop in HTTP/2 transport was disclosed.
Linuxsecurity
2026-05-22
CVE-2026-39821 published
A vulnerability allowing validation bypass and privilege escalation was disclosed.
Linuxsecurity
2026-06-19
SUSE releases security update
SUSE released version 10.32.4 for azure-storage-azcopy to address multiple vulnerabilities.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track SuSE and CVE-2025-47907 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed