Security Flaw in Mechanize Library Affects Website Automation
CVE-2026-107714

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107714?

The Mechanize library, widely used for automating interactions with websites, has a vulnerability where the HTTP agent does not consistently treat redirects according to the scheme and port. This can lead to sensitive information, such as Authorization and Cookie headers, being transmitted in plain text during a same-host redirect from HTTPS to HTTP. Additionally, it can unintentionally reveal caller-supplied Cookie headers to different services on the same host. These issues arise due to the separation of cookies in the Mechanize cookie jar. The vulnerability can expose credentials and is addressed in version 2.14.1.

Affected Version(s)

mechanize < 2.15.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.