All 6 CVE vulnerabilities found in mechanize, with AI-generated Chinese analysis, references, and POCs.
Vendor: sparklemotion
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-107715 | Mechanize sends credential headers to another host after an HTTP redirect CWE-200 | 6.8 | Medium | 2026-10-08 |
| CVE-2026-107714 | Mechanize sends credential headers to a different scheme or port after a redirect CWE-200 | 5.9 | Medium | 2026-10-08 |
| CVE-2026-107399 | Mechanize sends credential headers to another origin after a meta refresh CWE-200 | 6.8 | Medium | 2026-10-08 |
| CVE-2021-32837 | mechanize vulnerable to ReDoS CWE-1333 | 7.5 | High | 2023-01-17 |
| CVE-2022-31033 | Authorization header leak in rubygem Mechanize CWE-200 | 5.9 | Medium | 2022-06-09 |
| CVE-2021-21289 | Command Injection Vulnerability in Mechanize CWE-78 | 7.4 | High | 2021-02-02 |
All 6 known CVE vulnerabilities affecting mechanize with full Chinese analysis, references, and POCs where available.