Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-88880: Renovate may leak credentials via malicious GitLab redirects
CVE-2026-88880 · published 1 month ago
Summary
If you use Renovate to automate updates from a GitLab server, a specially crafted response can cause Renovate to send authentication details to an attacker‑controlled site. This happens because Renovate does not check where the pagination links point. Update Renovate to the latest version to stop this behavior and protect your credentials.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| renovatebot | renovate |
< 44.11.3 < 15.4.0 < 10.4.0 |
Original advisory text
Renovate before 44.11.3 Credential Exfiltration via Link Header
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-88880 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88880... Vendor Advisory
- https://github.com/renovatebot/renovate/security/advisories/GHSA-9hmg-9h89-jhmx
- https://www.vulncheck.com/advisories/renovate-before-44.11.3-credential-exfiltra...
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
9.2
Critical
Type
CWE-601Open Redirect
Timeline
Published10 Sep 2026
Updated11 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta