Ruby Mechanize flaw leaks credentials via cross-origin redirects
CVE-2026-107715 (CVSS 6.8) in Ruby Mechanize before 2.14.1 causes global headers such as Authorization tokens and cookies to be re-applied to cross-origin redirect requests, exposing credentials to attacker-controlled hosts. A PoC exists and the issue is patched in version 2.14.1.
- CVE-2026-107715: CVSS 6.8, CWE-200, network attack vector
- Affects Mechanize versions below 2.14.1; fixed in 2.14.1
- Global Authorization and cookie headers leak to untrusted hosts on redirect
- Public PoC available; not listed in CISA KEV
Read next
Security