{
  "id": 13090979,
  "title": "CVE-2026-107715: CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections",
  "url": "https://urgent.news/2026/10/09/cve-2026-107715-cve-2026-107715-information-disclosure-and-credential",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T10:30:59.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/cverports/cve-2026-107715-cve-2026-107715-information-disclosure-and-credential-leakage-in-ruby-mechanize-54j6"
  },
  "original_language": "en",
  "account": "CVE-2026-107715 identifies a security vulnerability impacting the Ruby Mechanize library prior to version 2.14.1. This flaw allows information disclosure and credential leakage through cross-origin HTTP redirects. When Mechanize agents perform cross-origin redirects, global headers like Authorization tokens or session cookies are erroneously re-applied to subsequent requests. This bypasses the system's internal header-stripping mechanism. An attacker controlling the redirection endpoint could capture sensitive bearer tokens or session cookies. The vulnerability is rated with a CVSS score of 6.8, classified as medium severity. Although a Proof of Concept (PoC) exploit is available, as of now, there is no official exploit in circulation. This issue has been addressed in Ruby Mechanize version 2.14.1, which patches the header-stripping logic in redirects. Upgrading to this version is strongly recommended to mitigate the risk.",
  "summary": "CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections Vulnerability ID: CVE-2026-107715 CVSS Score: 6.8 Published: 2026-10-08 Ruby Mechanize prior to version 2.14.1 contains an information disclosure vulnerability. When executing cross-origin HTTP redirects, global headers configured on the Mechanize agent (such as Authorization or Session…",
  "key_points": [
    "CVE-2026-107715 affects Ruby Mechanize library versions prior to 2.14.1",
    "Information disclosure and credential leakage via cross-origin HTTP redirects",
    "Upgrading to Mechanize 2.14.1 patches the vulnerability"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}