SUSE Azure-Storage-AzCopy Faces Multiple Security Vulnerabilities

SUSE Azure-Storage-AzCopy Faces Multiple Security Vulnerabilities

First seen 19 Jun 2026, 23:54 UTC Linuxsecurity 96% similarity 70.5

Article Content

Browse articles
ThreatCluster

SUSE has released an important update for azure-storage-azcopy addressing several vulnerabilities. The update includes fixes for CVE-2025-47907, CVE-2026-33186, CVE-2026-33814, CVE-2026-34986, and CVE-2026-39821. Notably, CVE-2026-33186 has a CVSS score of 9.1, indicating a high severity due to an authorization bypass vulnerability. CVE-2026-34986 allows for denial of service through crafted JWE input. Other vulnerabilities involve improper validation and infinite loops that could lead to service disruptions. The update is critical for users of azure-storage-azcopy, particularly those relying on HTTP/2 transport. Administrators are urged to apply the update to mitigate potential risks. The vulnerabilities were disclosed between 2025 and 2026, with some having public proof-of-concept code available.

Key Points: • SUSE released an important security update for azure-storage-azcopy on June 19, 2026. • Critical vulnerabilities include CVE-2026-33186 (CVSS 9.1) and CVE-2026-34986, which can lead to denial of service. • Administrators are advised to update to version 10.32.4 to address these vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2025-08-07
CVE-2025-47907 published
A vulnerability in database/sql was disclosed, causing incorrect results from Rows.Scan.
Linuxsecurity
2026-03-20
CVE-2026-33186 published
An authorization bypass vulnerability due to improper validation of HTTP/2 path pseudo-header was disclosed.
Linuxsecurity
2026-04-06
CVE-2026-34986 published
A crafted JWE input vulnerability leading to denial of service was disclosed.
Linuxsecurity
2026-04-07
First public PoC for CVE-2026-33186
Proof-of-concept code for the authorization bypass vulnerability was made publicly available.
Linuxsecurity
2026-05-07
CVE-2026-33814 published
A vulnerability causing an infinite loop in HTTP/2 transport was disclosed.
Linuxsecurity
2026-05-22
CVE-2026-39821 published
A vulnerability allowing validation bypass and privilege escalation was disclosed.
Linuxsecurity
2026-06-19
SUSE releases security update
SUSE released version 10.32.4 for azure-storage-azcopy to address multiple vulnerabilities.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story