VYPR

mechanize

by Sparklemotion

CVEs (3)

  • CVE-2026-107715MedOct 8, 2026
    risk 0.37cvss 6.8epss —

    The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even…

  • CVE-2026-107399MedOct 8, 2026
    risk 0.37cvss 6.8epss —

    The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another…

  • CVE-2026-107714MedOct 8, 2026
    risk 0.31cvss 5.9epss —

    The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize::HTTP::Agent#response_redirect treats redirects as same-origin when the host matches without consistently comparing scheme and port. A same-host HTTPS-to-HTTP redirect can send…