PT-2026-108216 · Rubygems · Mechanize
CVE-2026-107715
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mechanize versions prior to 2.14.1
Description
Mechanize leaks caller-supplied credential headers to a different host during an HTTP redirect. This occurs because
Mechanize#request headers= is reapplied by Mechanize::HTTP::Agent#request add headers even after Mechanize::HTTP::Agent#response redirect strips per-request headers. Additionally, the protected header lists omit Proxy-Authorization and Cookie2. An attacker controlling a redirect target can capture bearer tokens or session cookies supplied through request headers= or the per-request headers argument. This issue is limited to headers set manually by the caller; cookies in Mechanize#cookie jar and credentials in Mechanize::HTTP::AuthStore are not affected.Recommendations
Update to version 2.14.1.
As a temporary workaround, set
Mechanize#redirect ok to false and handle redirects explicitly.
Avoid using request headers= for credentials and instead pass them per-request only to trusted hosts.Fix
Information Disclosure
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mechanize