Junglewise Threat Intelligence

CVE-2026-44503: Microsoft Kiota libraries sensitive header leak in RedirectHandler

CVE-2026-44503 · Severity: high · CVSS 4 · Published 2026-05-14

Vendors: Microsoft, PyPI, NuGet, Go, Maven.

Executive brief

Microsoft Kiota libraries, which are used to build web API clients like the Microsoft Graph SDK, contain a security flaw in how they handle web redirects. When a trusted service redirects a user to a different website, the library fails to remove sensitive information like session cookies and proxy credentials from the request. An attacker who can trigger such a redirect could steal these credentials to hijack user sessions or access private corporate data.

Technical details

The vulnerability exists in the RedirectHandler middleware across several Kiota language implementations (Java, .NET, Python, TypeScript, and Go). While the handler correctly strips the 'Authorization' header during cross-host or cross-scheme redirects, it fails to remove 'Cookie', 'Proxy-Authorization', and other custom sensitive headers. In the Java implementation, this occurs because the default KiotaClientFactory disables OkHttp's native (and secure) redirect handling in favor of a custom implementation that only checks for the 'Authorization' header. An attacker capable of triggering a redirect (e.g., via an open redirect on a trusted domain) can capture these sensitive headers. Patches are available for all affected language ecosystems.

Affected products

  • Microsoft microsoft-kiota-abstractions < 1.9.1
  • Microsoft Microsoft.Kiota.Abstractions < 1.22.0
  • Microsoft microsoft-kiota-http < 1.9.9
  • Microsoft kiota-typescript < 1.0.0-preview.100
  • Microsoft kiota-http-go < 1.5.5

Timeline

  • 2026-04-30: disclosed: Initial disclosure by gavinbarron
  • 2026-05-07: advisory: GitHub Advisory published
  • 2026-05-14: advisory: NVD published CVE-2026-44503

References