Renovate 是一款依赖项更新工具。当它与 GitHub.com、GitHub Enterprise Cloud 或 GitHub Enterprise Server 进行交互时,会遵循 GitHub 服务器在 HTTP 响应头中提供的分页链接,并将为该主机配置的凭证发送到指定为“下一页”的 URL。由于分页 URL 未针对最初连接的主机进行验证,一个恶意或被入侵的 GitHub 服务器可以返回一个指向攻击者控制主机的 头,从而导致 Renovate 向该主机泄露其凭证。利用此漏洞的前提是,Renovate 交
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| renovatebot | renovate | 0 ~ 44.11.3 | - |
|
| renovatebot | renovate | 0 ~ 44.11.3 | - |
|
| renovatebot | renovate | 0 ~ 44.11.3 | - |
|
| renovatebot | renovate | 0 ~ 44.11.3 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 10.4.0 | - |
|
| renovatebot | renovate | 0 ~ 10.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88882 | 8.6 HIGH | Renovate before 44.11.2 Credential Exfiltration via Link Header |
| CVE-2026-88880 | 8.6 HIGH | Renovate before 44.11.3 Credential Exfiltration via Link Header |
| CVE-2026-88887 | 8.6 HIGH | Renovate before 44.11.2 Credential Exfiltration via Link Header |
| CVE-2026-88886 | 7.8 HIGH | Renovate before 44.14.7 Command Injection via gradle-wrapper |
| CVE-2026-88889 | 7.8 HIGH | Renovate before 44.14.7 Command Injection via distributionType |
| CVE-2026-88883 | 7.7 HIGH | Renovate before 44.14.4 TLS Private Key Log Sanitisation |
| CVE-2026-88885 | 7.0 HIGH | Renovate before 44.14.7 Command Injection via depName |
| CVE-2026-88888 | 7.0 HIGH | Renovate before 44.14.7 Command Injection via Mix organization |
| CVE-2026-88884 | 5.8 MEDIUM | Renovate before 44.3.1 Authentication Bypass via Digest Updates |
No comments yet