{"id":"GHSA-2mwr-xjcg-37j7","summary":"Mechanize sends credential headers to another host after an HTTP redirect","details":"## Summary\n\n`mechanize` leaked credentials to the redirect target when an HTTP redirect crossed to another host. Credentials set through `Mechanize#request_headers=` leaked even when they were `Authorization`.\n\n## Details\n\nTwo defects, both in `lib/mechanize/http/agent.rb`.\n\n**1. `Mechanize#request_headers=` bypassed the redirect strip entirely.** `#request_add_headers` copied `@request_headers` onto every request unconditionally, with no host check, including the request issued after a redirect. The strip in `#response_redirect` mutated only the per-request headers hash and never touched agent state. Because `request_headers=` is the documented way to set a default credential for every request, the header the code explicitly protected — `Authorization` — was the one most likely to leak.\n\n**2. The strip list omitted `Proxy-Authorization` and `Cookie2`.** Only `CREDENTIAL_HEADERS = ['Authorization']` and `COOKIE_HEADERS = ['Cookie']` were removed from the per-request headers hash on a cross-host redirect.\n\nCookies held in `Mechanize#cookie_jar` and credentials held in `Mechanize::HTTP::AuthStore` are **not** affected. Both are looked up per-URI, so they never follow a redirect to a foreign host. The exposure was limited to headers the caller set by hand.\n\n## PoC\n\n```ruby\nagent = Mechanize.new\nagent.request_headers = { 'Authorization' =\u003e 'Bearer secret' }\nagent.get('https://example.test/redirects-to-attacker')\n# the request to the attacker's host carries \"Authorization: Bearer secret\"\n```\n\n## Impact\n\nAn attacker who controls a redirect target — through an open redirect on the site being fetched, an attacker-supplied fetch URL, DNS rebinding, or MITM — captures bearer tokens and session cookies from any `mechanize` agent that sets credentials through `request_headers=` or the per-request `headers` argument. Disclosure only; no integrity or availability impact.\n\n## Patches\n\nFixed in `mechanize` v2.14.1.\n\n- Credentials and cookies are withheld from a request that follows a redirect across an origin, from **both** header sources: the per-request `headers` argument and `Mechanize#request_headers=`.\n- `CREDENTIAL_HEADERS` gains `Proxy-Authorization`; `COOKIE_HEADERS` gains `Cookie2`.\n\n`Proxy-Authorization` is withheld here although curl does not withhold it, because `Net::HTTP` tunnels `https:` requests with `CONNECT`, so a caller-supplied `Proxy-Authorization` travels inside the tunnel to the origin server rather than to the proxy.\n\nHeaders set through `Mechanize#request_headers=` no longer reach a redirect target on another origin when they are credentials. Callers that relied on the previous behavior will see those headers withheld.\n\n### What this fix does not cover\n\nOnly the headers in `CREDENTIAL_HEADERS` and `COOKIE_HEADERS` are withheld. A caller-supplied header that carries a credential under some other name — `X-API-Key`, `X-Vault-Token`, or any bespoke token header — still follows a redirect to another origin, matching the behavior of curl's `CURLOPT_HTTPHEADER`. If you set such a header, do not enable redirect following for requests that carry it, or scope it to a single request whose destination you control.\n\n## Workarounds\n\nSet `Mechanize#redirect_ok = false` and handle redirects explicitly, or avoid `request_headers=` for credentials and pass them per-request only to hosts you intend to authenticate to.\n\n## Credit\n\nReported by @SnailSploit.","aliases":["CVE-2026-107715"],"modified":"2026-10-08T22:15:07.251994937Z","published":"2026-10-08T22:09:00Z","database_specific":{"cwe_ids":["CWE-200","CWE-522"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-08T22:09:00Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/sparklemotion/mechanize/security/advisories/GHSA-2mwr-xjcg-37j7"},{"type":"WEB","url":"https://github.com/sparklemotion/mechanize/pull/676"},{"type":"WEB","url":"https://github.com/sparklemotion/mechanize/commit/02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f"},{"type":"WEB","url":"https://github.com/sparklemotion/mechanize/commit/94e0902867296be804f36eccbb47acf7d5018745"},{"type":"WEB","url":"https://github.com/sparklemotion/mechanize/commit/ac49abf2869297d83c3b11bbfb8b18e63b588c95"},{"type":"PACKAGE","url":"https://github.com/sparklemotion/mechanize"},{"type":"WEB","url":"https://github.com/sparklemotion/mechanize/releases/tag/v2.14.1"}],"affected":[{"package":{"name":"mechanize","ecosystem":"RubyGems","purl":"pkg:gem/mechanize"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.14.1"}]}],"versions":["0.1.0","0.1.1","0.1.2","0.1.3","0.2.0","0.2.1","0.2.2","0.2.3","0.3.0","0.3.1","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","0.5.0","0.5.1","0.5.2","0.5.3","0.5.4","0.6.0","0.6.1","0.6.10","0.6.11","0.6.2","0.6.3","0.6.4","0.6.5","0.6.6","0.6.7","0.6.8","0.6.9","0.7.0","0.7.1","0.7.2","0.7.3","0.7.4","0.7.5","0.7.6","0.7.7","0.7.8","0.8.0","0.8.1","0.8.2","0.8.3","0.8.4","0.8.5","0.9.0","0.9.1","0.9.2","0.9.3","1.0.0","1.0.1.beta.20110107104205","2.0","2.0.1","2.0.pre.1","2.0.pre.2","2.1","2.1.1","2.1.pre.1","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.12.2","2.13.0","2.14.0","2.2","2.2.1","2.3","2.4","2.5","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.7.6","2.7.7","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4","2.8.5","2.9.0","2.9.1","2.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-2mwr-xjcg-37j7/GHSA-2mwr-xjcg-37j7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}