{"id":"CVE-2026-44503","aliases":["GHSA-7j59-v9qr-6fq9","GO-2026-5224","PYSEC-2026-2647"],"url":"https://o3.security/vulnerability/CVE-2026-44503","summary":"Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect","details":"The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all custom headers are forwarded to the redirect target.","published":"2026-05-14T15:58:57.772Z","modified":"2026-08-07T11:31:01.532232162Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/microsoft/kiota-http-go","fixedVersion":"1.5.5"},{"ecosystem":"Maven","name":"com.microsoft.kiota:microsoft-kiota-abstractions","fixedVersion":"1.9.1"},{"ecosystem":"npm","name":"kiota-typescript","fixedVersion":"1.0.0-preview.100"},{"ecosystem":"NuGet","name":"Microsoft.Kiota.Abstractions","fixedVersion":"1.22.0"},{"ecosystem":"PyPI","name":"microsoft-kiota-http","fixedVersion":"1.9.9"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44503.json"},{"type":"ADVISORY","url":"https://github.com/microsoft/kiota-java/security/advisories/GHSA-7j59-v9qr-6fq9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44503"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:01.532232162Z"}}