Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88882— Renovate before 44.11.2 Credential Exfiltration via Link Header

Quick assessment

Affected
renovatebot renovate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Renovate 是一款依赖更新自动化工具。在 44.11.2 之前的版本中(以及 Mend Renovate CE/EE 镜像和图表早于 15.4.0,以及 mend-renovate-enterprise-edition Helm 图表早于 10.4.0),当从 NuGet 注册表列出新的软件包版本时,Renovate 会直接跟随注册表在 HTTP 头中提供的分页 URL,而未验证目标是否具有与已配置注册表相同的源(origin)。由于分页请求会附带注册表凭证,因此一个恶意或被攻陷的 NuGet 注册表可以返回

CVSS 8.6 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88882

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Renovate before 44.11.2 Credential Exfiltration via Link Header
Source: CVE Program / CVE List V5
Vulnerability Description
Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the HTTP `Link` header without verifying that the target has the same origin as the configured registry. Registry credentials are attached to the request for the 'next' page, so a malicious or compromised NuGet registry can return a `Link` header pointing at an attacker-controlled server and cause Renovate to send the registry credentials to that server. Exploitation requires the remote registry to be malicious or compromised; such a registry would normally already have received the credentials on the initial request, so the issue primarily allows the credentials to be delivered to an additional, attacker-chosen host. The fix restricts pagination to the same origin; the previous behaviour can be re-enabled with the RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN option.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
renovatebot renovate 0 ~ 44.11.2 -
renovatebot renovate 0 ~ 44.11.2 -
renovatebot renovate 0 ~ 44.11.2 -
renovatebot renovate 0 ~ 44.11.2 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 10.4.0 -
renovatebot renovate 0 ~ 10.4.0 -

II. Public POCs for CVE-2026-88882

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88882

登录查看更多情报信息。

Vendor Advisories for CVE-2026-88882 (2)

Same Patch Batch · renovatebot · 2026-09-10 · 10 CVEs total

CVE-2026-88880 8.6 HIGH Renovate before 44.11.3 Credential Exfiltration via Link Header
CVE-2026-88881 8.6 HIGH Renovate before 44.11.3 Credential Exfiltration via Link Header
CVE-2026-88887 8.6 HIGH Renovate before 44.11.2 Credential Exfiltration via Link Header
CVE-2026-88886 7.8 HIGH Renovate before 44.14.7 Command Injection via gradle-wrapper
CVE-2026-88889 7.8 HIGH Renovate before 44.14.7 Command Injection via distributionType
CVE-2026-88883 7.7 HIGH Renovate before 44.14.4 TLS Private Key Log Sanitisation
CVE-2026-88885 7.0 HIGH Renovate before 44.14.7 Command Injection via depName
CVE-2026-88888 7.0 HIGH Renovate before 44.14.7 Command Injection via Mix organization
CVE-2026-88884 5.8 MEDIUM Renovate before 44.3.1 Authentication Bypass via Digest Updates

IV. Related Vulnerabilities

V. Comments for CVE-2026-88882

No comments yet


Leave a comment