Credential Exfiltration in Renovate Dependency Update Tool
CVE-2026-88881
9.2CRITICAL
What is CVE-2026-88881?
The Renovate Dependency Update Tool is susceptible to a credential exfiltration vulnerability due to improper validation of pagination URLs supplied in the HTTP 'Link' header from GitHub servers. When interacting with GitHub.com or its enterprise versions, Renovate may inadvertently send sensitive credentials to a malicious or compromised server. This risk arises when the pagination links lead to an attacker-controlled domain, thereby exposing user credentials. This issue demands immediate attention, as exploitation necessitates the pre-condition of communicating with a compromised GitHub host.
Affected Version(s)
renovate 0 < 44.11.3
renovate 0 < 44.11.3
renovate 0 < 44.11.3
