CVE-2026-107715: CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections
CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections Vulnerability ID: CVE-2026-107715 CVSS Score: 6.8 Published: 2026-10-08 Ruby Mechanize prior to version 2.14.1 contains an information disclosure vulnerability. When executing cross-origin HTTP redirects, global headers configured on the Mechanize agent (such as Authorization or Session…
CVE-2026-107715 identifies a security vulnerability impacting the Ruby Mechanize library prior to version 2.14.1. This flaw allows information disclosure and credential leakage through cross-origin HTTP redirects. When Mechanize agents perform cross-origin redirects, global headers like Authorization tokens or session cookies are erroneously re-applied to subsequent requests.
This bypasses the system's internal header-stripping mechanism. An attacker controlling the redirection endpoint could capture sensitive bearer tokens or session cookies. The vulnerability is rated with a CVSS score of 6.8, classified as medium severity. Although a Proof of Concept (PoC) exploit is available, as of now, there is no official exploit in circulation.
This issue has been addressed in Ruby Mechanize version 2.14.1, which patches the header-stripping logic in redirects. Upgrading to this version is strongly recommended to mitigate the risk.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.