The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2mwr-xjcg-37j7 Mechanize sends credential headers to another host after an HTTP redirect
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1.
Title Mechanize sends credential headers to another host after an HTTP redirect
Weaknesses CWE-200
CWE-522
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T21:27:24.651Z

Reserved: 2026-10-08T17:21:52.975Z

Link: CVE-2026-107715

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T22:17:27.163

Modified: 2026-10-08T22:17:27.163

Link: CVE-2026-107715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses