Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88884— Renovate before 44.3.1 Authentication Bypass via Digest Updates

Quick assessment

Affected
renovatebot renovate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Renovate 是一个依赖项更新自动化工具。在 44.3.1 版本之前(以及 Mend Renovate CE/EE 镜像 15.4.0 之前、mend-renovate-ce Helm 图表 15.4.0 之前、mend-renovate-enterprise-edition Helm 图表 10.4.0 之前),摘要(digest)更新未受内部 (稳定期)检查的约束。 当仓库配置了 ,且存在 的依赖项——例如固定到某个提交 SHA 但带有浮动标签的 GitHub Actions、Docker 镜像、Go 模块

CVSS 5.8 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88884

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Renovate before 44.3.1 Authentication Bypass via Digest Updates
Source: CVE Program / CVE List V5
Vulnerability Description
Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updates are not subject to the internal `minimumReleaseAge` (stability age) checks. When a repository configures `minimumReleaseAge` and has dependencies with `updateType=digest` — for example GitHub Actions pinned to a commit SHA with a floating tag, Docker images, Go modules or NuGet packages — Renovate will still open a pull request for a newly published digest, marked only with a pending `renovate/stability-days` status check. A newly published, potentially malicious dependency version can therefore cause a PR to be raised and CI workflows to potentially run before the configured minimum release age has elapsed, which is precisely what the Minimum Release Age control is intended to prevent. The issue is fixed in Renovate 44.3.1; as a workaround, digest updates can be disabled or gated behind `dependencyDashboardApproval`.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
renovatebot renovate 0 ~ 44.3.1 -
renovatebot renovate 0 ~ 44.3.1 -
renovatebot renovate 0 ~ 44.3.1 -
renovatebot renovate 0 ~ 44.3.1 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 15.4.0 -
renovatebot renovate 0 ~ 10.4.0 -
renovatebot renovate 0 ~ 10.4.0 -

II. Public POCs for CVE-2026-88884

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88884

登录查看更多情报信息。

Vendor Advisories for CVE-2026-88884 (2)

Same Patch Batch · renovatebot · 2026-09-10 · 10 CVEs total

CVE-2026-88882 8.6 HIGH Renovate before 44.11.2 Credential Exfiltration via Link Header
CVE-2026-88880 8.6 HIGH Renovate before 44.11.3 Credential Exfiltration via Link Header
CVE-2026-88881 8.6 HIGH Renovate before 44.11.3 Credential Exfiltration via Link Header
CVE-2026-88887 8.6 HIGH Renovate before 44.11.2 Credential Exfiltration via Link Header
CVE-2026-88886 7.8 HIGH Renovate before 44.14.7 Command Injection via gradle-wrapper
CVE-2026-88889 7.8 HIGH Renovate before 44.14.7 Command Injection via distributionType
CVE-2026-88883 7.7 HIGH Renovate before 44.14.4 TLS Private Key Log Sanitisation
CVE-2026-88885 7.0 HIGH Renovate before 44.14.7 Command Injection via depName
CVE-2026-88888 7.0 HIGH Renovate before 44.14.7 Command Injection via Mix organization

IV. Related Vulnerabilities

V. Comments for CVE-2026-88884

No comments yet


Leave a comment