{"id":"RUSTSEC-2026-0275","title":"Legacy `azure_core` writes the `authorization` header value to logs","summary":"Legacy `azure_core` writes the `authorization` header value to logs","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","vendor":"azure_core","product":"azure_core","ecosystem":"rust","affected":["azure_core >= 0.2.1-0, < 0.22.0"],"patched":["azure_core 0.22.0"],"published":"2026-08-15","updated":"2026-09-01","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0275","references":[{"url":"https://crates.io/crates/azure_core"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0275.html"},{"url":"https://github.com/Azure/azure-sdk-for-rust/issues/5074"},{"url":"https://github.com/Azure/azure-sdk-for-rust/pull/1699"},{"url":"https://github.com/Azure/azure-sdk-for-rust/commit/7a0e20c1e002ce06da0f3ec8795ef1529862ea97"}],"tags":["osv","rust"],"ingestedAt":"2026-09-02T19:31:28.103Z","slug":"RUSTSEC-2026-0275","body":"## Overview\n\nApplications built on the legacy Azure SDK for Rust (`azure_core` 0.21.0 and\nearlier) write the value of the outgoing `authorization` header to their logs\nwhenever debug-level logging is enabled, and in every affected version also at\ntrace level. The leaked values are live credentials — Microsoft Entra\nID bearer tokens, Azure Storage SharedKey signatures, and SAS tokens — and\nanyone with read access to the logs can replay them until they expire\n(CWE-532).\n\nVersions 0.22.0 and later, which are the rewritten and currently supported\nSDK, do not contain the affected code.\n\n## Affected versions\n\nEvery published legacy version except 0.2.0 writes the `authorization` header\nvalue to logs: 0.1.1 (2022-01-25), and 0.2.1 through 0.21.0 (2024-10-15).\n\n## Mitigation\n\n- Upgrade to `azure_core` 1.0.0 or newer.\n- If you are unable to upgrade, raise the log level above debug for the\n  impacted crates or submit a feature request for missing crates built on `azure_core` 1.0.0 or newer.\n- Treat logs produced by an affected build as credential-bearing: rotate any\n  long-lived secret that authenticated a request while debug logging was on.\n\n## Coordination\n\nThe finding was reported to the Microsoft Security Response Center\n(VULN-211331), which determined that it does not meet the Microsoft Security\nServicing Criteria definition of a security vulnerability.\n\nIt was then disclosed publicly as [Azure/azure-sdk-for-rust#5074][issue] on\n2026-08-15, asking the maintainers to confirm the behavior so that an advisory\ncould be filed for the legacy crates. A maintainer replied on 2026-08-26 and\nclosed the issue as not planned: the `legacy` branch is unsupported, there are\nno plans to update it, and users should move to crates built on `azure_core`\n1.0.0 or newer.\n\n[pr]: https://github.com/Azure/azure-sdk-for-rust/pull/1699\n[issue]: https://github.com/Azure/azure-sdk-for-rust/issues/5074\n\n## Affected packages\n\n- `azure_core >= 0.2.1-0, < 0.22.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `azure_core 0.22.0`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}