CVE-2026-107714: Mechanize sends credential headers to a different scheme or port after a redirect
The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize::HTTP::Agent#responseredirect treats redirects as same-origin when the host matches without consistently comparing scheme and port. A same-host HTTPS-to-HTTP redirect can send Authorization and Cookie headers over cleartext, while a same-host redirect to another port can send a caller-supplied Cookie header to a different service. Cookies in Mechanize#cookiejar remain scoped separately; the issue affects caller-supplied headers and can disclose credentials without affecting integrity or availability. This issue is fixed in version 2.14.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mechanizeto a version that resolves this vulnerability.Fixed in 2.14.1
Event History
Frequently Asked Questions
Which applications are exposed to credential disclosure?
Applications using Mechanize before 2.14.1 are exposed when they supply Authorization or Cookie headers and follow a redirect to the same host with a different scheme or port. The issue concerns caller-supplied headers; cookies held in Mechanize's cookie jar remain separately scoped.
What redirect conditions are required for exploitation?
An attacker must cause or control a redirect whose hostname matches the original destination but changes from HTTPS to HTTP, or changes to another port. HTTPS-to-HTTP redirects can disclose Authorization and Cookie headers over cleartext, while redirects to another port can disclose a caller-supplied Cookie header to a different service.
Does this vulnerability affect integrity or availability?
No. The described impact is credential disclosure; it does not affect integrity or availability.
What version fixes the issue?
Upgrade Mechanize to version 2.14.1, which fixes the redirect origin comparison behavior.