chiprook
← Security
SecurityOctober 9, 2026, 17:30

Ruby Mechanize flaw leaks credentials via cross-origin redirects

CVE-2026-107715 (CVSS 6.8) in Ruby Mechanize before 2.14.1 causes global headers such as Authorization tokens and cookies to be re-applied to cross-origin redirect requests, exposing credentials to attacker-controlled hosts. A PoC exists and the issue is patched in version 2.14.1.

Ruby Mechanize flaw leaks credentials via cross-origin redirects
#Ruby#Mechanize
Read next
Security

GitLab EE CVE-2026-87719: critical 9.9 flaw leaks search credentials

Security

ShinyHunters hacked Clop leak site via Grav CMS path traversal flaw

Security

Coolify flaw let password-reset tokens be redirected to attacker hosts

Security

Amazon Bedrock AgentCore SDK flaws exposed AWS credentials