CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections
Vulnerability ID: CVE-2026-107715
CVSS Score: 6.8
Published: 2026-10-08
Ruby Mechanize prior to version 2.14.1 contains an information disclosure vulnerability. When executing cross-origin HTTP redirects, global headers configured on the Mechanize agent (such as Authorization or Session Cookies) are dynamically re-applied to the subsequent request, bypassing the internal header-stripping logic. An attacker who controls a redirection endpoint can capture sensitive bearer tokens or cookies.
TL;DR
Mechanize prior to 2.14.1 fails to prevent caller-supplied global credentials from being transmitted to untrusted hosts during cross-origin HTTP redirections, exposing sensitive credentials to third parties.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-200
- Attack Vector: Network (High Complexity)
- CVSS v3.1: 6.8 (Medium)
- Exploit Status: Proof of Concept (PoC) available
- CISA KEV Status: Not Listed
- Remediation Status: Patched in v2.14.1
Affected Systems
- Ruby Mechanize library prior to 2.14.1
-
mechanize: < 2.14.1 (Fixed in:
2.14.1)
Code Analysis
Commit: 02a1235
Fix Proxy-Authorization and Cookie2 stripping logic in Mechanize redirects
Commit: 94e0902
Ensure persistent request headers do not bypass redirect credential stripping logic
Commit: ac49abf
Prevent POST request body entity headers from leaking into redirect GET queries
Commit: a40941e
Tag release version v2.14.1 with security fixes for header disclosure
Mitigation Strategies
- Upgrade Mechanize to version 2.14.1 or higher.
- Avoid using global
Mechanize#request_headers=to assign sensitive values like API tokens. - Disable automatic redirects by setting
agent.redirect_ok = falseand handling HTTP redirections manually with host domain checks.
Remediation Steps:
- Open the Gemfile of your Ruby application.
- Locate the
mechanizegem dependency line. - Update the dependency constraint to
gem 'mechanize', '>= 2.14.1'. - Run
bundle update mechanizeto download and apply the patch. - Verify the installation using
bundle info mechanizeto confirm it is running version 2.14.1 or greater.
References
- GHSA-2mwr-xjcg-37j7: Mechanize Credential Leakage on HTTP Redirect
- Mechanize PR 676: Strip credentials on redirect properly
- Mechanize Release Tag v2.14.1
Read the full report for CVE-2026-107715 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)