Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-88882: Renovate can leak registry credentials to other sites
CVE-2026-88882 · published 1 month ago
Summary
Renovate versions before 44.11.2 may follow pagination links from a NuGet package source without checking if the link points to the same server. If a malicious or compromised registry supplies a link to an attacker-controlled site, Renovate will send the stored credentials to that site. Update to the latest version or configure the tool to disallow cross‑origin pagination to stop this from happening.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| renovatebot | renovate |
< 44.11.2 < 15.4.0 < 10.4.0 |
Original advisory text
Renovate before 44.11.2 Credential Exfiltration via Link Header
Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the HTTP `Link` header without verifying that the target has the same origin as the configured registry. Registry credentials are attached to the request for the 'next' page, so a malicious or compromised NuGet registry can return a `Link` header pointing at an attacker-controlled server and cause Renovate to send the registry credentials to that server. Exploitation requires the remote registry to be malicious or compromised; such a registry would normally already have received the credentials on the initial request, so the issue primarily allows the credentials to be delivered to an additional, attacker-chosen host. The fix restricts pagination to the same origin; the previous behaviour can be re-enabled with the RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN option.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88882... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-88882 Vendor Advisory
- https://github.com/renovatebot/renovate/security/advisories/GHSA-rh7w-ccch-gh49
- https://www.vulncheck.com/advisories/renovate-before-44.11.2-credential-exfiltra...
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
9.2
Critical
Type
CWE-601Open Redirect
Timeline
Published10 Sep 2026
Updated11 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta