VYPR

Kiota Java

by Microsoft

Source repositories

CVEs (11)

  • CVE-2026-59866CriJul 16, 2026
    risk 0.54cvss epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when…

  • CVE-2026-59865CriJul 16, 2026
    risk 0.54cvss epss 0.03

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation..dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as…

  • CVE-2026-59864CriJul 16, 2026
    risk 0.54cvss epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot…

  • CVE-2026-41134HigApr 22, 2026
    risk 0.51cvss 7.8epss 0.00

    Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings, URL template metadata,…

  • CVE-2026-59860HigJul 16, 2026
    risk 0.50cvss epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// … comments). When…

  • CVE-2026-59859HigJul 16, 2026
    risk 0.50cvss epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in…

  • CVE-2026-59861HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby…

  • CVE-2026-59867HigJul 16, 2026
    risk 0.39cvss 7.1epss 0.02

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-controlled or attacker-influenced description…

  • CVE-2026-59863HigJul 16, 2026
    risk 0.39cvss epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a…

  • CVE-2026-44503HigMay 14, 2026
    risk 0.39cvss epss 0.01

    The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed;…

  • CVE-2026-59862HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and…