mechanize vulnerabilities
CVEs whose affected-version data names the mechanize package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-107715Medium· 6.8The Mechanize library is used for automating interaction with websites
The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize:…
▾ Sunlitmechanize · mechanizeEPSS 0.40%via NVD
CVE-2026-107399Medium· 6.8The Mechanize library is used for automating interaction with websites
The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A p…
▾ Sunlitmechanize · mechanizevia NVD