๐Ÿ” CVE Alert

CVE-2026-107714

MEDIUM 5.9

Mechanize sends credential headers to a different scheme or port after a redirect

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize::HTTP::Agent#response_redirect treats redirects as same-origin when the host matches without consistently comparing scheme and port. A same-host HTTPS-to-HTTP redirect can send Authorization and Cookie headers over cleartext, while a same-host redirect to another port can send a caller-supplied Cookie header to a different service. Cookies in Mechanize#cookie_jar remain scoped separately; the issue affects caller-supplied headers and can disclose credentials without affecting integrity or availability. This issue is fixed in version 2.14.1.

CWE CWE-200 CWE-319 CWE-522
Vendor sparklemotion
Product mechanize
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for sparklemotion mechanize

Be the first to know when new medium vulnerabilities affecting sparklemotion mechanize are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

sparklemotion / mechanize
< 2.15.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sparklemotion/mechanize/security/advisories/GHSA-5jgv-wc2m-xv99 github.com: https://github.com/sparklemotion/mechanize/pull/676 github.com: https://github.com/sparklemotion/mechanize/commit/02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f github.com: https://github.com/sparklemotion/mechanize/commit/2f97fe358a91928e5e48221f2ec5cb50fa1a43ba github.com: https://github.com/sparklemotion/mechanize/releases/tag/v2.14.1