Credential Exfiltration Vulnerability in Renovate by Renovatebot
CVE-2026-88880
9.2CRITICAL
What is CVE-2026-88880?
The Renovate product prior to version 44.11.3 is susceptible to a vulnerability that allows malicious actors to manipulate Link headers when interacting with GitLab server pagination. This flaw enables attackers controlling a compromised GitLab server to redirect sensitive requests to their own infrastructure, potentially leading to the exfiltration of authentication credentials from users. Protecting against this vulnerability involves updating to the latest version of Renovate to ensure the validation of Link header destinations.
Affected Version(s)
renovate 0 < 44.11.3
renovate 0 < 44.11.3
renovate 0 < 44.11.3
