DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107715: CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections

CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections

Vulnerability ID: CVE-2026-107715
CVSS Score: 6.8
Published: 2026-10-08

Ruby Mechanize prior to version 2.14.1 contains an information disclosure vulnerability. When executing cross-origin HTTP redirects, global headers configured on the Mechanize agent (such as Authorization or Session Cookies) are dynamically re-applied to the subsequent request, bypassing the internal header-stripping logic. An attacker who controls a redirection endpoint can capture sensitive bearer tokens or cookies.

TL;DR

Mechanize prior to 2.14.1 fails to prevent caller-supplied global credentials from being transmitted to untrusted hosts during cross-origin HTTP redirections, exposing sensitive credentials to third parties.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-200
  • Attack Vector: Network (High Complexity)
  • CVSS v3.1: 6.8 (Medium)
  • Exploit Status: Proof of Concept (PoC) available
  • CISA KEV Status: Not Listed
  • Remediation Status: Patched in v2.14.1

Affected Systems

  • Ruby Mechanize library prior to 2.14.1
  • mechanize: < 2.14.1 (Fixed in: 2.14.1)

Code Analysis

Commit: 02a1235

Fix Proxy-Authorization and Cookie2 stripping logic in Mechanize redirects

Commit: 94e0902

Ensure persistent request headers do not bypass redirect credential stripping logic

Commit: ac49abf

Prevent POST request body entity headers from leaking into redirect GET queries

Commit: a40941e

Tag release version v2.14.1 with security fixes for header disclosure

Mitigation Strategies

  • Upgrade Mechanize to version 2.14.1 or higher.
  • Avoid using global Mechanize#request_headers= to assign sensitive values like API tokens.
  • Disable automatic redirects by setting agent.redirect_ok = false and handling HTTP redirections manually with host domain checks.

Remediation Steps:

  1. Open the Gemfile of your Ruby application.
  2. Locate the mechanize gem dependency line.
  3. Update the dependency constraint to gem 'mechanize', '>= 2.14.1'.
  4. Run bundle update mechanize to download and apply the patch.
  5. Verify the installation using bundle info mechanize to confirm it is running version 2.14.1 or greater.

References


Read the full report for CVE-2026-107715 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)