Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing kiota generate on an attacker-controlled or attacker-influenced description to perform build-time SSRF, remote file inclusion, and local file inclusion by inlining external schemas such as REMOTEKIOTAPROP or Leaked into generated clients. This issue is fixed in version 1.29.1 and 1.32.5 by AllowedExternalOriginsStreamLoader and the --allowed-external-origins option.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59867.json",
"cwe_ids": [
"CWE-22",
"CWE-829",
"CWE-918"
]
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "1.30.0"
},
{
"fixed": "1.31.1"
},
{
"introduced": "0"
},
{
"fixed": "1.29.1"
}
]
}
[
{
"id": "CVE-2026-59867-0255b0db",
"source": "https://github.com/microsoft/kiota/commit/70cd8bcba3ff1815f93187f3eb80ef96fd194d46",
"signature_type": "Line",
"target": {
"file": "it/java/gh/src/test/java/GHAPITest.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"66609017551477010826143835577406265593",
"35496344713004664179944048284480170529",
"147500007851372202392601133532187874810",
"240753228186878202917022054237087631710",
"322801780681153563118919792465691120440",
"105331927903652750006918956054969541779",
"92754106178057991798446179728179208061",
"253209821667215414607528288804099395645",
"250008073155348665397373185331785853495",
"64797852886090781921647040874546962214"
]
},
"signature_version": "v1",
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59867.json"
"2026-08-19T09:06:20Z"