CVE-2026-49336
Published:June 19, 2026
Updated:August 04, 2026
@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, "@microsoft/kiota-http-fetchlibrary"'s "RedirectHandler" is documented as stripping "Authorization" and "Cookie" from cross-origin redirect targets, but the default "scrubSensitiveHeaders" callback in "RedirectHandlerOptions" uses case-sensitive property deletion ("delete headers.Authorization", "delete headers.Cookie") on a headers object that "FetchRequestAdapter.getRequestFromRequestInformation" has already lower-cased. The delete therefore targets keys that do not exist, the scrub is a no-op, and any Bearer token or Cookie attached by a kiota-generated SDK is forwarded to an attacker-controlled host across a 30x redirect. This is reachable in the default middleware chain ("MiddlewareFactory.getDefaultMiddlewares") with no custom configuration, and applies to every kiota-generated TypeScript SDK that uses "BaseBearerTokenAuthenticationProvider" or any other authentication provider that sets the "Authorization" request header. Version 1.0.0-preview.102 patches the issue.
Affected Packages
https://github.com/microsoft/kiota-typescript.git (GITHUB):
Affected version(s) >=@microsoft/kiota-http-fetchlibrary@1.0.0-preview.97 <@microsoft/kiota-http-fetchlibrary@1.0.0-preview.102Fix Suggestion:
Update to version @microsoft/kiota-http-fetchlibrary@1.0.0-preview.102@microsoft/kiota-http-fetchlibrary (NPM):
Affected version(s) >=1.0.0-preview.97 <1.0.0-preview.102Fix Suggestion:
Update to version 1.0.0-preview.102Related Resources (5)
Do you need more information?
Contact UsCVSS v4
Base Score:
5.5
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
Exploit Maturity
POC
CVSS v3
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE
Weakness Type (CWE)
EPSS
Base Score:
1.18