---
id: RUSTSEC-2026-0275
title: Legacy `azure_core` writes the `authorization` header value to logs
summary: Legacy `azure_core` writes the `authorization` header value to logs
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
vendor: azure_core
product: azure_core
ecosystem: rust
affected:
  - 'azure_core >= 0.2.1-0, < 0.22.0'
patched:
  - azure_core 0.22.0
published: '2026-08-15'
updated: '2026-09-01'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0275'
references:
  - url: 'https://crates.io/crates/azure_core'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0275.html'
  - url: 'https://github.com/Azure/azure-sdk-for-rust/issues/5074'
  - url: 'https://github.com/Azure/azure-sdk-for-rust/pull/1699'
  - url: >-
      https://github.com/Azure/azure-sdk-for-rust/commit/7a0e20c1e002ce06da0f3ec8795ef1529862ea97
tags:
  - osv
  - rust
ingestedAt: '2026-09-02T19:31:28.103Z'
---

## Overview

Applications built on the legacy Azure SDK for Rust (`azure_core` 0.21.0 and
earlier) write the value of the outgoing `authorization` header to their logs
whenever debug-level logging is enabled, and in every affected version also at
trace level. The leaked values are live credentials — Microsoft Entra
ID bearer tokens, Azure Storage SharedKey signatures, and SAS tokens — and
anyone with read access to the logs can replay them until they expire
(CWE-532).

Versions 0.22.0 and later, which are the rewritten and currently supported
SDK, do not contain the affected code.

## Affected versions

Every published legacy version except 0.2.0 writes the `authorization` header
value to logs: 0.1.1 (2022-01-25), and 0.2.1 through 0.21.0 (2024-10-15).

## Mitigation

- Upgrade to `azure_core` 1.0.0 or newer.
- If you are unable to upgrade, raise the log level above debug for the
  impacted crates or submit a feature request for missing crates built on `azure_core` 1.0.0 or newer.
- Treat logs produced by an affected build as credential-bearing: rotate any
  long-lived secret that authenticated a request while debug logging was on.

## Coordination

The finding was reported to the Microsoft Security Response Center
(VULN-211331), which determined that it does not meet the Microsoft Security
Servicing Criteria definition of a security vulnerability.

It was then disclosed publicly as [Azure/azure-sdk-for-rust#5074][issue] on
2026-08-15, asking the maintainers to confirm the behavior so that an advisory
could be filed for the legacy crates. A maintainer replied on 2026-08-26 and
closed the issue as not planned: the `legacy` branch is unsupported, there are
no plans to update it, and users should move to crates built on `azure_core`
1.0.0 or newer.

[pr]: https://github.com/Azure/azure-sdk-for-rust/pull/1699
[issue]: https://github.com/Azure/azure-sdk-for-rust/issues/5074

## Affected packages

- `azure_core >= 0.2.1-0, < 0.22.0`

## Remediation

Upgrade to a patched release:

- `azure_core 0.22.0`
