Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88883— Renovate before 44.14.4 TLS Private Key Log Sanitisation

Quick assessment

Affected
renovatebot renovate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Renovate 是一个自动化的依赖更新工具。在 44.14.4 之前的版本中(以及 Mend Renovate CE/EE 镜像 15.4.0 之前、mend-renovate-enterprise-edition Helm Chart 10.4.0 之前),针对用于双向 TLS(Mutual TLS)的 TLS 私钥的日志脱敏处理并不完整。虽然 字段本身的值会被掩盖(redacted),但如果该私钥值出现在其他位置——例如在其他配置项中,或出现在日志中并非 键下的消息里——那么该私钥值就不会被掩盖,导致完整的私

CVSS 7.7 · High

Possible ATT&CK Techniques 1 AI

T1560 · Archive Collected Data
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88883

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Renovate before 44.14.4 TLS Private Key Log Sanitisation
Source: CVE Program / CVE List V5
Vulnerability Description
Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].httpsPrivateKey was redacted in the field itself, the same private key value was not redacted if it also appeared elsewhere — for example in another configuration option or in a log message under a key other than httpsPrivateKey — causing the full private key to be written to Renovate's logs in cleartext. This affects deployments that configure Mutual TLS through hostRules[].httpsPrivateKey without passing the value through the documented `secrets` configuration. Anyone able to read the resulting logs can recover the private key. The issue is fixed in Renovate 44.14.4, which redacts any value supplied as hostRules[].httpsPrivateKey wherever it appears in the logs; as a workaround, supply the key via the `secrets` configuration.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
renovatebot renovate 0 ~ 44.14.44 -
renovatebot renovate 0 ~ 44.14.44 -
renovatebot renovate 0 ~ 44.14.44 -
renovatebot renovate 0 ~ 44.14.44 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 10.4.0 -
renovatebot renovate 0 ~ 10.4.0 -

II. Public POCs for CVE-2026-88883

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88883

登录查看更多情报信息。

Vendor Advisories for CVE-2026-88883 (2)

Same Patch Batch · renovatebot · 2026-09-10 · 10 CVEs total

CVE-2026-88882 8.6 HIGH Renovate before 44.11.2 Credential Exfiltration via Link Header
CVE-2026-88880 8.6 HIGH Renovate before 44.11.3 Credential Exfiltration via Link Header
CVE-2026-88881 8.6 HIGH Renovate before 44.11.3 Credential Exfiltration via Link Header
CVE-2026-88887 8.6 HIGH Renovate before 44.11.2 Credential Exfiltration via Link Header
CVE-2026-88886 7.8 HIGH Renovate before 44.14.7 Command Injection via gradle-wrapper
CVE-2026-88889 7.8 HIGH Renovate before 44.14.7 Command Injection via distributionType
CVE-2026-88885 7.0 HIGH Renovate before 44.14.7 Command Injection via depName
CVE-2026-88888 7.0 HIGH Renovate before 44.14.7 Command Injection via Mix organization
CVE-2026-88884 5.8 MEDIUM Renovate before 44.3.1 Authentication Bypass via Digest Updates

IV. Related Vulnerabilities

V. Comments for CVE-2026-88883

No comments yet


Leave a comment