mechanize
Mechanize is a ruby library that makes automated web interaction easy.
Activity
- Latest release
- 3w ago
- Total releases
- 95
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Downloads
- 41.6M
- Stars
- 4.4k
Details
- License
- MIT
- First release
- Jan 26, 2005
| Version | Released | |
|---|---|---|
2.14.1
patch
|
2.14.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.14.0
minor
|
2.14.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.13.0
minor
|
2.13.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.12.2
patch
|
2.12.2
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.12.1
patch
|
2.12.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.12.0
minor
|
2.12.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.11.0
minor
|
2.11.0
minor
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
2.10.1
patch
|
2.10.1
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
2.10.0
minor
|
2.10.0
minor
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
2.9.2
patch
|
2.9.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.9.1
patch
|
2.9.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.9.0
minor
|
2.9.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.8.5
patch
|
2.8.5
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.8.4
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
2.8.4
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.8.3
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
2.8.3
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.8.2
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
2.8.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.8.1
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
2.8.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.8.0
minor
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
2.8.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.7.7
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
2.7.7
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.7.6
patch
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.7.6
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.7.5
patch
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.7.5
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.7.4
patch
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.7.4
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.7.3
patch
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.7.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.7.2
patch
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.7.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.7.1
patch
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.7.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.7.0
minor
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.7.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.6.0
minor
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.6.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.5.1
patch
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.5.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.5
minor
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.5
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.4
minor
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.4
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.3
minor
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.3
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.2.1
patch
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.2.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.2
minor
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.2
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.1.1
patch
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.1.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.1
minor
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.1
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.1.pre.1
pre
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.1.pre.1
pre
Dependencies (8)
Changelog
Compare changes
|
|
2.0.1
patch
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.0.1
patch
Dependencies (6)
Changelog
Compare changes
|
|
2.0
major
2 CVEs
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21289
GHSA-qrqm-fpv6-6r8g
Feb 02, 2021
Command Injection Vulnerability in Mechanize
7.4
/ 10
High
Network
Low
None
Required
Changed
None
High
None
This security advisory has been created for public disclosure of a Command Injection vulnerability that was responsibly reported by @kyoshidajp (Katsuhiko YOSHIDA). ImpactMechanize
PatchesThese vulnerabilities are patched in Mechanize v2.7.7. WorkaroundsNo workarounds are available. We recommend upgrading to v2.7.7 or later. ReferencesSee https://docs.rubocop.org/rubocop/cops_security.html#securityopen for background on why For more informationIf you have any questions or comments about this advisory, please open an issue in sparklemotion/mechanize. Affected versions
2.0
2.0.1
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
+ 7 more Show less
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
Fixed in
2.7.7
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.pre.2
pre
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.0.pre.1
pre
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.9.3
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.9.2
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.9.1
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.8.5
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.8.4
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.8.3
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.8.1
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.8.2
patch
1 CVE
CVE-2022-31033
GHSA-64qm-hrgp-pgr9
Jun 09, 2022
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Summary Mechanize (rubygem) Mitigation Upgrade to Mechanize v2.8.5 or later. Notes See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
+ 71 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.1.beta.20110107104205
2.0
2.0.1
2.0.pre.1
2.0.pre.2
2.1
2.1.1
2.1.pre.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
Fixed in
2.8.5
References
Updated Nov 08, 2023 · Source: OSV.dev |