Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2mwr-xjcg-37j7 | Mechanize sends credential headers to another host after an HTTP redirect |
Thu, 08 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1. | |
| Title | Mechanize sends credential headers to another host after an HTTP redirect | |
| Weaknesses | CWE-200 CWE-522 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T21:27:24.651Z
Reserved: 2026-10-08T17:21:52.975Z
Link: CVE-2026-107715
No data.
Status : Received
Published: 2026-10-08T22:17:27.163
Modified: 2026-10-08T22:17:27.163
Link: CVE-2026-107715
No data.
OpenCVE Enrichment
No data.
Github GHSA