CVE-2026-107714: Mechanize sends credential headers to a different scheme or port after a redirect

Published Oct 8, 2026
·
Updated

The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize::HTTP::Agent#responseredirect treats redirects as same-origin when the host matches without consistently comparing scheme and port. A same-host HTTPS-to-HTTP redirect can send Authorization and Cookie headers over cleartext, while a same-host redirect to another port can send a caller-supplied Cookie header to a different service. Cookies in Mechanize#cookiejar remain scoped separately; the issue affects caller-supplied headers and can disclose credentials without affecting integrity or availability. This issue is fixed in version 2.14.1.

Affected Software

1 affected component
rubygems/mechanize<2.14.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Mechanize to a version that resolves this vulnerability.

    Fixed in 2.14.1

Event History

Oct 8, 2026
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which applications are exposed to credential disclosure?

Applications using Mechanize before 2.14.1 are exposed when they supply Authorization or Cookie headers and follow a redirect to the same host with a different scheme or port. The issue concerns caller-supplied headers; cookies held in Mechanize's cookie jar remain separately scoped.

2

What redirect conditions are required for exploitation?

An attacker must cause or control a redirect whose hostname matches the original destination but changes from HTTPS to HTTP, or changes to another port. HTTPS-to-HTTP redirects can disclose Authorization and Cookie headers over cleartext, while redirects to another port can disclose a caller-supplied Cookie header to a different service.

3

Does this vulnerability affect integrity or availability?

No. The described impact is credential disclosure; it does not affect integrity or availability.

4

What version fixes the issue?

Upgrade Mechanize to version 2.14.1, which fixes the redirect origin comparison behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203