Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-88881: Renovate can leak credentials to attacker site
CVE-2026-88881 · published 1 month ago
Summary
Renovate, the tool that automatically updates software libraries, can be tricked into sending its stored GitHub credentials to a malicious server when it follows pagination links in GitHub responses. If the GitHub server it talks to is compromised, an attacker could receive those credentials. Update Renovate to version 44.11.3 or later to stop this behavior; there is no safe temporary workaround.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| renovatebot | renovate |
< 44.11.3 < 15.4.0 < 10.4.0 |
Original advisory text
Renovate before 44.11.3 Credential Exfiltration via Link Header
Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials configured for that host to the URL given as the 'next' page. Because the pagination URL is not validated against the host originally contacted, a malicious or compromised GitHub server can return a `Link` header pointing to an attacker-controlled host and cause Renovate to disclose those credentials to it. Exploitation requires that the GitHub server Renovate talks to (as the repository host or as a datasource such as github-releases, github-tags, or git-refs) is already malicious or compromised. The issue is fixed in renovate 44.11.3 (npm and renovate/renovate container images), Mend Renovate CE/EE images and the mend-renovate-ce helm chart 15.4.0, and the mend-renovate-enterprise-edition helm chart 10.4.0. There is no workaround; the pre-existing RENOVATE_X_REBASE_PAGINATION_LINKS option disables the new host check and should only be used with servers that intentionally use different pagination hosts.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88881... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-88881 Vendor Advisory
- https://github.com/renovatebot/renovate/security/advisories/GHSA-w57v-h33h-835c
- https://www.vulncheck.com/advisories/renovate-before-44.11.3-credential-exfiltra...
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
9.2
Critical
Type
CWE-601Open Redirect
Timeline
Published10 Sep 2026
Updated11 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta