CVE 7 HIGH

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect_CVE-2026-44503

7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Description

The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all custom headers are forwarded to the redirect target.

Basic Information

ID CVE-2026-44503
Source GitHub_M
Published May 14, 2026 at 15:58

Affected Product

Vendor microsoft
Product kiota-java
Version < 1.9.1
Affected Versions microsoft kiota-java < 1.9.1
microsoft Microsoft.Kiota.Abstractions < 1.22.0
microsoft github.com/microsoft/kiota-http-go < 1.5.5
microsoft kiota-typescript < 1.0.0-preview.100
microsoft microsoft-kiota-abstractions < 1.9.1
microsoft microsoft-kiota-http < 1.9.9

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.