Kiota Java Libraries是Microsoft开源的一个用于生成OpenAPI SDK的Java基础库集合。 Kiota Java Libraries 1.9.0版本存在输入验证错误漏洞,该漏洞源于RedirectHandler中间件在遵循3xx重定向到不同主机或方案时未能剥离敏感HTTP头,仅移除Authorization头,Cookie、Proxy-Authorization和所有自定义头被转发到重定向目标。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| microsoft | github.com/microsoft/kiota-http-go | < 1.5.5 |
affected |
| microsoft | kiota-java | < 1.9.1 |
affected |
| microsoft | kiota-typescript | < 1.0.0-preview.100 |
affected |
| microsoft | microsoft-kiota-abstractions | < 1.9.1 |
affected |
| microsoft | microsoft-kiota-http | < 1.9.9 |
affected |
| microsoft | Microsoft.Kiota.Abstractions | < 1.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| microsoft | kiota-java | < 1.9.1 | - |
|
| microsoft | Microsoft.Kiota.Abstractions | < 1.22.0 | - |
|
| microsoft | github.com/microsoft/kiota-http-go | < 1.5.5 | - |
|
| microsoft | kiota-typescript | < 1.0.0-preview.100 | - |
|
| microsoft | microsoft-kiota-abstractions | < 1.9.1 | - |
|
| microsoft | microsoft-kiota-http | < 1.9.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41615 | 9.6 CRITICAL | Microsoft Authenticator Information Disclosure Vulnerability |
| CVE-2026-42897 | 8.1 HIGH | Microsoft Exchange Server Spoofing Vulnerability |
No comments yet