CVE-2026-49336 Details
Description
@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, `@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documented as stripping `Authorization` and `Cookie` from cross-origin redirect targets, but the default `scrubSensitiveHeaders` callback in `RedirectHandlerOptions` uses case-sensitive property deletion (`delete headers.Authorization`, `delete headers.Cookie`) on a headers object that `FetchRequestAdapter.getRequestFromRequestInformation` has already lower-cased. The delete therefore targets keys that do not exist, the scrub is a no-op, and any Bearer token or Cookie attached by a kiota-generated SDK is forwarded to an attacker-controlled host across a 30x redirect. This is reachable in the default middleware chain (`MiddlewareFactory.getDefaultMiddlewares`) with no custom configuration, and applies to every kiota-generated TypeScript SDK that uses `BaseBearerTokenAuthenticationProvider` or any other authentication provider that sets the `Authorization` request header. Version 1.0.0-preview.102 patches the issue.
A vulnerability exists in the '@microsoft/kiota-http-fetchlibrary' versions 1.0.0-preview.97 prior to 1.0.0-preview.102. The issue arises in the 'RedirectHandler' component, where the default 'scrubSensitiveHeaders' function fails to properly remove 'Authorization' and 'Cookie' headers from cross-origin redirect targets. This failure is due to a case-sensitivity mismatch: the headers are lowercased before reaching the redirect handler, but the scrub function attempts to delete them using case-sensitive property names. As a result, any Bearer token or Cookie attached by a Kiota-generated SDK is inadvertently forwarded to an attacker-controlled host during a 30x redirect.
Users can update to '@microsoft/kiota-http-fetchlibrary' version 1.0.0-preview.102 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 19, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/microsoft/kiota-typescript/security/advisories/GHSA-396q-4vc8-28x9 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/microsoft/kiota-typescript/commit/09f8bd9b34d68bf412a9b78f6ca7e7961ef14974 | [email protected] | Source CodeVendor |
| https://github.com/microsoft/kiota-typescript/security/advisories/GHSA-396q-4vc8-28x9 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-178 | Improper Handling of Case Sensitivity | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Microsoft @microsoft/kiota-http-fetchlibrary | >= 1.0.0-preview.97, <= 1.0.0-preview.101 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |
Volerion