CVE Database
/

CVE-2026-44503

Back to search

CVE-2026-44503

Published: May 14, 2026

Modified: May 14, 2026

PUBLISHED

Description

The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all custom headers are forwarded to the redirect target.

VendorProductVersions

microsoft

kiota-java

affected
< 1.9.1

microsoft

Microsoft.Kiota.Abstractions

affected
< 1.22.0

microsoft

github.com/microsoft/kiota-http-go

affected
< 1.5.5

microsoft

kiota-typescript

affected
< 1.0.0-preview.100

microsoft

microsoft-kiota-abstractions

affected
< 1.9.1

microsoft

microsoft-kiota-http

affected
< 1.9.9

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now