CVE-2026-44503: Microsoft Github.com/microsoft/kiota-HTTP-Go

High severity, CVSS 7.0. EPSS: 0.9% chance of exploitation in the next 30 days.

The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all custom headers are forwarded to the redirect target.

Affected products

  • Microsoft Github.com/microsoft/kiota-HTTP-Go: before 1.5.5 (fixed in 1.5.5)
  • Microsoft Kiota-Java: before 1.9.1 (fixed in 1.9.1)
  • Microsoft Kiota-TypeScript: before 1.0.0-preview.100 (fixed in 1.0.0-preview.100)
  • Microsoft Microsoft-Kiota-Abstractions: before 1.9.1 (fixed in 1.9.1)
  • Microsoft Microsoft-Kiota-HTTP: before 1.9.9 (fixed in 1.9.9)
  • Microsoft Microsoft.kiota.abstractions: before 1.22.0 (fixed in 1.22.0)

Published 2026-05-14. Last modified 2026-06-17.