CVE-2026-44503 | Microsoft kiota-java prior 1.9.1 Authorization Header redirect (GHSA-7j59-v9qr-6fq9)
A vulnerability described as problematic has been identified in Microsoft kiota-java, Microsoft.Kiota.Abstractions, kiota-http-go, kiota-typescript, -kiota-abstractions and microsoft-kiota-http. This issue affects some unknown processing of the component Authorization Header Handler. Executing a manipulation can lead to open redirect.
This vulnerability appears as CVE-2026-44503. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.