Vulnerability library
Security checkJune 26, 2026

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

@microsoft/kiota-http-fetchlibrary’s RedirectHandler is documented as stripping Authorization and Cookie from cross-origin redirect targets, but the default scrubSensitiveHeaders callback in RedirectHandlerOptions uses case-sensitive property deletion (delete headers.Authorization, delete headers.Cookie) on a headers object that FetchRequestAdapter.getRequestFromRequestInformation has already lower-cased.

Recommendation

Update the @microsoft/kiota-http-fetchlibrary package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 1.0.0-preview.97, <= 1.0.0-preview.101
  • Patched version(s): 1.0.0-preview.102

References

Could your website be exposed too?

SmartScanner can check your website for @microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated June 26, 2026