PT-2026-38408 · Microsoft · Microsoft-Kiota-Http-Okhttp+5

Michaelmainer

·

Published

2026-05-07

·

Updated

2026-06-25

·

CVE-2026-44503

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions microsoft-kiota-http-okHttp versions 1.9.0 and earlier kiota-dotnet (affected versions not specified) kiota-java (affected versions not specified) kiota-python (affected versions not specified) kiota-typescript (affected versions not specified) kiota-http-go (affected versions not specified)
Description The RedirectHandler middleware fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. While the Authorization header is removed, other sensitive headers including Cookie, Proxy-Authorization, and custom headers are forwarded to the redirect target. This occurs within the getRedirect() function. An attacker capable of triggering a cross-origin redirect from a trusted API could capture session cookies, proxy credentials, and API keys from the redirected request, potentially leading to session hijacking or credential theft.
Recommendations Update microsoft-kiota-http-okHttp to a version later than 1.9.0. At the moment, there is no information about a newer version that contains a fix for this vulnerability for kiota-dotnet, kiota-java, kiota-python, kiota-typescript, and kiota-http-go.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-CN27900
CLEANSTART-2026-CQ05396
CLEANSTART-2026-FU07345
CLEANSTART-2026-HB39135
CLEANSTART-2026-NM83456
CLEANSTART-2026-UI95341
CLEANSTART-2026-XB69243
CLEANSTART-2026-YG71543
CVE-2026-44503
GHSA-7J59-V9QR-6FQ9
GO-2026-5224

Affected Products

Kiota-Dotnet
Kiota-Http-Go
Kiota-Java
Kiota-Python
Kiota-Typescript
Microsoft-Kiota-Http-Okhttp