Sensitive Header Exposure in Microsoft Kiota Libraries
CVE-2026-44503

7HIGH

What is CVE-2026-44503?

The RedirectHandler middleware in certain Microsoft Kiota libraries does not adequately protect sensitive HTTP headers during 3xx redirects. This flaw allows critical headers, such as Cookie, Proxy-Authorization, and custom headers, to be transmitted to untrusted targets, potentially exposing sensitive data to attackers. Only the Authorization header is properly removed in these scenarios. It is crucial for developers to assess their use of the affected libraries and implement suitable protections to mitigate risks associated with this vulnerability.

Affected Version(s)

github.com/microsoft/kiota-http-go < 1.5.5

kiota-java < 1.9.1

kiota-typescript < 1.0.0-preview.100

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.