Mechanize 库用于自动化与网站的交互。在 2.14.1 版本之前,Mechanize 会在 HTTP 重定向后将调用者提供的认证头部信息发送至不同的主机。具体而言,即使 方法会清除每个请求的头部信息, 仍会重新应用通过 设置的头部。此外,受保护的头部列表未排除 和 。攻击者若能控制重定向目标,则可捕获通过 或每请求头部参数提供的承载令牌(bearer tokens)或会话 cookie;但 和 不受此问题影响。该问题已在 2.14.1 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sparklemotion | mechanize | < 2.15.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107399 | 6.8 MEDIUM | Mechanize sends credential headers to another origin after a meta refresh |
| CVE-2026-107714 | 5.9 MEDIUM | Mechanize sends credential headers to a different scheme or port after a redirect |
No comments yet