HIGHMaven →
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
Affected packages
- Microsoft.Kiota.Abstractions— before 1.22.0
- com.microsoft.kiota:microsoft-kiota-abstractions— before 1.9.1
- github.com/microsoft/kiota-http-go
- kiota-typescript
- microsoft-kiota-http— before 1.9.9
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/microsoft/kiota-java/security/advisories/GHSA-7j59-v9qr-6fq9
- https://nvd.nist.gov/vuln/detail/CVE-2026-44503
- https://github.com/advisories/GHSA-7j59-v9qr-6fq9
- https://github.com/microsoft/kiota-java
- https://github.com/pypa/advisory-database/tree/main/vulns/microsoft-kiota-http/PYSEC-2026-2647.yaml
- https://pypi.org/project/microsoft-kiota-http
Structured record: https://osv.dev/vulnerability/GHSA-7j59-v9qr-6fq9
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta