Junglewise Threat Intelligence

CVE-2026-49336: Microsoft Kiota TypeScript sensitive header leak in RedirectHandler

CVE-2026-49336 · Severity: medium · CVSS 4 · Published 2026-06-19

Vendors: Microsoft, npm.

Executive brief

The Microsoft Kiota HTTP FetchLibrary is used by TypeScript applications to make authenticated API calls to services like Microsoft Graph. Due to a case-sensitivity bug in the redirect handler, Bearer tokens and session cookies are leaked to attacker-controlled hosts when the application follows HTTP redirects across domain boundaries. An attacker can exploit this through MITM attacks, compromised API endpoints, or by tricking the application into calling attacker-chosen URLs, resulting in unauthorized access to customer data and accounts.

Technical details

The vulnerability is a case-sensitivity mismatch in the redirect credential scrubber. FetchRequestAdapter.getRequestFromRequestInformation normalizes all header keys to lowercase (e.g., "Authorization" → "authorization"), but the default scrubSensitiveHeaders callback in RedirectHandlerOptions attempts case-sensitive property deletion (delete headers.Authorization, delete headers.Cookie). Since the actual keys are lowercase, the delete statements fail silently, and sensitive headers pass through to the redirect target. This affects the default middleware chain with no opt-in required and applies to every TypeScript SDK generated by Kiota that uses bearer token or any other authentication provider setting the Authorization header. Affected versions are 1.0.0-preview.97 through 1.0.0-preview.101; patched in 1.0.0-preview.102 and later. The fix implements case-insensitive header removal.

Affected products

  • Microsoft @microsoft/kiota-http-fetchlibrary 1.0.0-preview.97 through 1.0.0-preview.101

Timeline

  • 2026-06-26: disclosed: GHSA-396q-4vc8-28x9 published
  • 2026-06-26: patched: Fix released in version 1.0.0-preview.102
  • 2026-02-27: other: Vulnerable code introduced in commit 74886cc4 (version 1.0.0-preview.97)
  • 2022-12-09: other: Case-lowercasing predates scrub in commit d612bac2

References