Sensitive Header Exposure in Microsoft Kiota Libraries
CVE-2026-44503
7HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 May 2026
What is CVE-2026-44503?
The RedirectHandler middleware in certain Microsoft Kiota libraries does not adequately protect sensitive HTTP headers during 3xx redirects. This flaw allows critical headers, such as Cookie, Proxy-Authorization, and custom headers, to be transmitted to untrusted targets, potentially exposing sensitive data to attackers. Only the Authorization header is properly removed in these scenarios. It is crucial for developers to assess their use of the affected libraries and implement suitable protections to mitigate risks associated with this vulnerability.
Affected Version(s)
github.com/microsoft/kiota-http-go < 1.5.5
kiota-java < 1.9.1
kiota-typescript < 1.0.0-preview.100