Open Redirect Affecting @microsoft/kiota-http-fetchlibrary package, versions <1.0.0-preview.100


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.08% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Open Redirect vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-MICROSOFTKIOTAHTTPFETCHLIBRARY-16699852
  • published15 May 2026
  • disclosed7 May 2026
  • creditMichael Mainer

Introduced: 7 May 2026

CVE-2026-44503  (opens in a new tab)
CWE-601  (opens in a new tab)

How to fix?

Upgrade @microsoft/kiota-http-fetchlibrary to version 1.0.0-preview.100 or higher.

Overview

@microsoft/kiota-http-fetchlibrary is an implementation using the Fetch API to make requests.

Affected versions of this package are vulnerable to Open Redirect in the RedirectHandler function. An attacker can obtain sensitive information such as session cookies, proxy credentials, and API keys by inducing a cross-host or cross-scheme redirect, causing these headers to be forwarded to an attacker-controlled server.

CVSS Base Scores

version 4.0
version 3.1