Renovate 是一个依赖项更新自动化工具。在获取容器镜像的标签/摘要列表时,Renovate 会遵循远程注册表在 HTTP Link 响应头中提供的分页链接,并在发起后续请求时附加该注册表的凭据,但并不会验证该分页 URL 是否与原始注册表具有相同的源(origin)。因此,恶意或已被攻陷的容器注册表可以通过 Link 响应头指定一个由攻击者控制的主机,从而获取到 Renovate 用于访问该注册表的凭据。利用此漏洞的前提是:目标系统已配置了容器(Docker)依赖项,并且已经与恶意或已被攻陷的注册表进行交互。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| renovatebot | renovate | 0 ~ 44.11.2 | - |
|
| renovatebot | renovate | 0 ~ 44.11.2 | - |
|
| renovatebot | renovate | 0 ~ 44.11.2 | - |
|
| renovatebot | renovate | 0 ~ 44.11.2 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 10.4.0 | - |
|
| renovatebot | renovate | 0 ~ 10.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88882 | 8.6 HIGH | Renovate before 44.11.2 Credential Exfiltration via Link Header |
| CVE-2026-88880 | 8.6 HIGH | Renovate before 44.11.3 Credential Exfiltration via Link Header |
| CVE-2026-88881 | 8.6 HIGH | Renovate before 44.11.3 Credential Exfiltration via Link Header |
| CVE-2026-88886 | 7.8 HIGH | Renovate before 44.14.7 Command Injection via gradle-wrapper |
| CVE-2026-88889 | 7.8 HIGH | Renovate before 44.14.7 Command Injection via distributionType |
| CVE-2026-88883 | 7.7 HIGH | Renovate before 44.14.4 TLS Private Key Log Sanitisation |
| CVE-2026-88885 | 7.0 HIGH | Renovate before 44.14.7 Command Injection via depName |
| CVE-2026-88888 | 7.0 HIGH | Renovate before 44.14.7 Command Injection via Mix organization |
| CVE-2026-88884 | 5.8 MEDIUM | Renovate before 44.3.1 Authentication Bypass via Digest Updates |
No comments yet