Upbound Official
provider-azuread
By upbound
Last changed 2 months ago
Availability
Community
Standard
Enterprise
Business Critical
Languages
Support
Upbound Supported
12 months window ends 2026/12/08
Security & Maintenance
CVE Remediation
Backporting
Upbound signed

Notice something off about this package? Help us keep the marketplace safe and trustworthy by reporting inappropriate content or behavior.

Report this package
Overview
Upbound's official Crossplane provider to manage Microsoft Azure Active Directory resources in Kubernetes.

Summary

This release includes critical security fixes for CVE vulnerabilities.

Highlights

  • Security vulnerability remediation: Updated Go version from 1.25.9 to 1.25.10
  • Fixed 11 CVEs: Including 6 High severity and 5 Medium severity vulnerabilities
    • CVE-2026-39820 (High)
    • CVE-2026-42499 (High)
    • CVE-2026-39836 (High)
    • CVE-2026-33814 (High)
    • CVE-2026-33811 (High)
    • CVE-2026-42501 (High)
    • CVE-2026-39817 (Medium)
    • CVE-2026-39826 (Medium)
    • CVE-2026-39825 (Medium)
    • CVE-2026-39823 (Medium)
    • CVE-2026-39819 (Medium)

All vulnerabilities were in the Go standard library and have been resolved with the Go version update.