CVE-2026-44503
Published: May 14, 2026
Modified: May 14, 2026
Description
The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all custom headers are forwarded to the redirect target.
| Vendor | Product | Versions |
|---|---|---|
microsoft | kiota-java | affected < 1.9.1 |
microsoft | Microsoft.Kiota.Abstractions | affected < 1.22.0 |
microsoft | github.com/microsoft/kiota-http-go | affected < 1.5.5 |
microsoft | kiota-typescript | affected < 1.0.0-preview.100 |
microsoft | microsoft-kiota-abstractions | affected < 1.9.1 |
microsoft | microsoft-kiota-http | affected < 1.9.9 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now