PT-2026-108216 · Rubygems · Mechanize

CVE-2026-107715

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mechanize versions prior to 2.14.1
Description Mechanize leaks caller-supplied credential headers to a different host during an HTTP redirect. This occurs because Mechanize#request headers= is reapplied by Mechanize::HTTP::Agent#request add headers even after Mechanize::HTTP::Agent#response redirect strips per-request headers. Additionally, the protected header lists omit Proxy-Authorization and Cookie2. An attacker controlling a redirect target can capture bearer tokens or session cookies supplied through request headers= or the per-request headers argument. This issue is limited to headers set manually by the caller; cookies in Mechanize#cookie jar and credentials in Mechanize::HTTP::AuthStore are not affected.
Recommendations Update to version 2.14.1. As a temporary workaround, set Mechanize#redirect ok to false and handle redirects explicitly. Avoid using request headers= for credentials and instead pass them per-request only to trusted hosts.

Fix

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107715
GHSA-2MWR-XJCG-37J7

Affected Products

Mechanize