CVE-2026-44503: Microsoft Github.com/microsoft/kiota-HTTP-Go
High severity, CVSS 7.0. EPSS: 0.9% chance of exploitation in the next 30 days.
The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all custom headers are forwarded to the redirect target.
Affected products
- Microsoft Github.com/microsoft/kiota-HTTP-Go: before 1.5.5 (fixed in 1.5.5)
- Microsoft Kiota-Java: before 1.9.1 (fixed in 1.9.1)
- Microsoft Kiota-TypeScript: before 1.0.0-preview.100 (fixed in 1.0.0-preview.100)
- Microsoft Microsoft-Kiota-Abstractions: before 1.9.1 (fixed in 1.9.1)
- Microsoft Microsoft-Kiota-HTTP: before 1.9.9 (fixed in 1.9.9)
- Microsoft Microsoft.kiota.abstractions: before 1.22.0 (fixed in 1.22.0)
Published 2026-05-14. Last modified 2026-06-17.