7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Description
The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all custom headers are forwarded to the redirect target.
Basic Information
ID
CVE-2026-44503
Source
GitHub_M
Published
May 14, 2026 at 15:58
Affected Product
Vendor
microsoft
Product
kiota-java
Version
< 1.9.1
Affected Versions
microsoft kiota-java < 1.9.1
microsoft Microsoft.Kiota.Abstractions < 1.22.0
microsoft github.com/microsoft/kiota-http-go < 1.5.5
microsoft kiota-typescript < 1.0.0-preview.100
microsoft microsoft-kiota-abstractions < 1.9.1
microsoft microsoft-kiota-http < 1.9.9
microsoft Microsoft.Kiota.Abstractions < 1.22.0
microsoft github.com/microsoft/kiota-http-go < 1.5.5
microsoft kiota-typescript < 1.0.0-preview.100
microsoft microsoft-kiota-abstractions < 1.9.1
microsoft microsoft-kiota-http < 1.9.9