CVE-2026-107714
Mechanize sends credential headers to a different scheme or port after a redirect
The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize::HTTP::Agent#response_redirect treats redirects as same-origin when the host matches without consistently comparing scheme and port. A same-host HTTPS-to-HTTP redirect can send Authorization and Cookie headers over cleartext, while a same-host redirect to another port can send a caller-supplied Cookie header to a different service. Cookies in Mechanize#cookie_jar remain scoped separately; the issue affects caller-supplied headers and can disclose credentials without affecting integrity or availability. This issue is fixed in version 2.14.1.
| CWE | CWE-200 CWE-319 CWE-522 |
| Vendor | sparklemotion |
| Product | mechanize |
| Published | Oct 8, 2026 |
Get instant alerts for sparklemotion mechanize
Be the first to know when new medium vulnerabilities affecting sparklemotion mechanize are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N