CVE-2025-65037: Microsoft Azure Container Apps

Critical severity, CVSS 10.0. EPSS: 1% chance of exploitation in the next 30 days.

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

Affected products

  • Microsoft Azure Container Apps: affected versions not specified

Published 2025-12-18. Last modified 2026-06-17.