PT-2026-38408 · Microsoft · Kiota-Dotnet+5

·

CVE-2026-44503

·

Published

2026-05-07

·

Updated

2026-07-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions microsoft-kiota-http-okHttp versions 1.9.0 and earlier kiota-dotnet (affected versions not specified) kiota-java (affected versions not specified) kiota-python (affected versions not specified) kiota-typescript (affected versions not specified) kiota-http-go (affected versions not specified)
Description The RedirectHandler middleware fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. While the Authorization header is removed, other sensitive headers including Cookie, Proxy-Authorization, and custom headers are forwarded to the redirect target. This occurs within the getRedirect() function. An attacker capable of triggering a cross-origin redirect from a trusted API could capture session cookies, proxy credentials, and API keys from the redirected request, potentially leading to session hijacking or credential theft.
Recommendations Update microsoft-kiota-http-okHttp to a version later than 1.9.0. At the moment, there is no information about a newer version that contains a fix for this vulnerability for kiota-dotnet, kiota-java, kiota-python, kiota-typescript, and kiota-http-go.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AN24336
CLEANSTART-2026-AR38431
CLEANSTART-2026-CN27900
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-FU07345
CLEANSTART-2026-GP34045
CLEANSTART-2026-HB39135
CLEANSTART-2026-KE11953
CLEANSTART-2026-KJ73757
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-SO50412
CLEANSTART-2026-UI95341
CLEANSTART-2026-UV44486
CLEANSTART-2026-XB69243
CLEANSTART-2026-YG71543
CLEANSTART-2026-ZF00349
CVE-2026-44503
ECHO-0E0D-C481-2581
GHSA-7J59-V9QR-6FQ9
GO-2026-5224
OPENSUSE-SU-2026:21483-1
PYSEC-2026-2647

Affected Products

Kiota-Dotnet
Kiota-Http-Go
Kiota-Java
Kiota-Python
Kiota-Typescript
Microsoft-Kiota-Http-Okhttp