Renovate 在 44.11.3 之前版本在跟踪 GitLab 服务器分页时,未能验证 头部中的目标地址,这使得恶意服务器可以将携带凭证的请求重定向到攻击者控制的资源。控制着某个已受损 GitLab 服务器的攻击者可以通过指定指向其自身基础设施的 头部,从而窃取认证凭证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| renovatebot | renovate | 0 ~ 44.11.3 | - |
|
| renovatebot | renovate | 0 ~ 44.11.3 | - |
|
| renovatebot | renovate | 0 ~ 44.11.3 | - |
|
| renovatebot | renovate | 0 ~ 44.11.3 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 10.4.0 | - |
|
| renovatebot | renovate | 0 ~ 10.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88882 | 8.6 HIGH | Renovate before 44.11.2 Credential Exfiltration via Link Header |
| CVE-2026-88881 | 8.6 HIGH | Renovate before 44.11.3 Credential Exfiltration via Link Header |
| CVE-2026-88887 | 8.6 HIGH | Renovate before 44.11.2 Credential Exfiltration via Link Header |
| CVE-2026-88886 | 7.8 HIGH | Renovate before 44.14.7 Command Injection via gradle-wrapper |
| CVE-2026-88889 | 7.8 HIGH | Renovate before 44.14.7 Command Injection via distributionType |
| CVE-2026-88883 | 7.7 HIGH | Renovate before 44.14.4 TLS Private Key Log Sanitisation |
| CVE-2026-88885 | 7.0 HIGH | Renovate before 44.14.7 Command Injection via depName |
| CVE-2026-88888 | 7.0 HIGH | Renovate before 44.14.7 Command Injection via Mix organization |
| CVE-2026-88884 | 5.8 MEDIUM | Renovate before 44.3.1 Authentication Bypass via Digest Updates |
No comments yet