Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-88880: Renovate may leak credentials via malicious GitLab redirects

CVE-2026-88880 · published 1 month ago
Summary

If you use Renovate to automate updates from a GitLab server, a specially crafted response can cause Renovate to send authentication details to an attacker‑controlled site. This happens because Renovate does not check where the pagination links point. Update Renovate to the latest version to stop this behavior and protect your credentials.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
renovatebot renovate < 44.11.3
< 15.4.0
< 10.4.0
Original advisory text
Renovate before 44.11.3 Credential Exfiltration via Link Header
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-601Open Redirect
Timeline
Published10 Sep 2026
Updated11 Oct 2026
First seen10 Sep 2026
Sources
CVE-2026-88880 · MITRE
Track software like this
Free during beta