CVE-2026-107715
Received Received - Intake

Mechanize Credential Header Exposure via Redirect

Vulnerability report for CVE-2026-107715, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sparklemotion mechanize < 2.15.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Mechanize library before version 2.14.1 has a flaw where it sends user-supplied credential headers to a different host after an HTTP redirect. This happens because Mechanize#request_headers= is reapplied even after Mechanize::HTTP::Agent#response_redirect strips per-request headers. Attackers controlling a redirect target could capture bearer tokens or session cookies sent via request_headers= or per-request headers.

Detection Guidance

Detecting this vulnerability requires checking the version of the Mechanize library in use. If your system uses Mechanize version 2.14.0 or earlier, it is vulnerable. Run the command 'gem list mechanize' to check the installed version.

Impact Analysis

An attacker could steal sensitive session cookies or authentication tokens by tricking you into visiting a malicious site that redirects to their server. This could lead to unauthorized access to your accounts or data if those credentials are reused elsewhere.

Mitigation Strategies

Upgrade the Mechanize library to version 2.14.1 or later. Use the command 'gem install mechanize -v 2.14.1' to update. Review any custom code that uses Mechanize#request_headers= or per-request headers to ensure sensitive headers are not exposed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107715. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart