HTTP Client Code Generator Vulnerability in Kiota by Microsoft
CVE-2026-59867

7.1HIGH

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-59867?

The Kiota HTTP Client code generator has a vulnerability that allows the resolution of OpenAPI $ref values by fetching remote HTTP(s) URLs and reading local file paths. This security flaw can be exploited using attacker-controlled OpenAPI descriptions, leading to build-time SSRF, remote file inclusion, and local file inclusion. The issue has been addressed in versions 1.29.1 and 1.32.5 by introducing the AllowedExternalOriginsStreamLoader and the --allowed-external-origins option to mitigate the risk of such attacks.

Affected Version(s)

kiota >= 1.30.0, < 1.31.1 < 1.30.0, 1.31.1

kiota < 1.29.1 < 1.29.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.