Mechanize 库用于自动化与网站的交互。在版本 2.14.1 之前, 方法在主机名匹配时,会将重定向视为同源(same-origin),但未一致地比较协议(scheme)和端口(port)。这可能导致以下安全问题: 在同一主机名下从 HTTPS 重定向到 HTTP 时,会明文发送 (授权)和 (Cookie)头部信息; 在同一主机名下重定向到不同端口时,可能会将调用方提供的 头部发送到另一个服务。 需要注意的是, 中的 Cookie 是独立作用域的,因此该漏洞不影响 Cookie 的完整性或可用性。但该漏洞会
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sparklemotion | mechanize | < 2.15.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107399 | 6.8 MEDIUM | Mechanize sends credential headers to another origin after a meta refresh |
| CVE-2026-107715 | 6.8 MEDIUM | Mechanize sends credential headers to another host after an HTTP redirect |
No comments yet