Credential Exfiltration in Renovate Dependency Update Tool
CVE-2026-88881

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88881?

The Renovate Dependency Update Tool is susceptible to a credential exfiltration vulnerability due to improper validation of pagination URLs supplied in the HTTP 'Link' header from GitHub servers. When interacting with GitHub.com or its enterprise versions, Renovate may inadvertently send sensitive credentials to a malicious or compromised server. This risk arises when the pagination links lead to an attacker-controlled domain, thereby exposing user credentials. This issue demands immediate attention, as exploitation necessitates the pre-condition of communicating with a compromised GitHub host.

Affected Version(s)

renovate 0 < 44.11.3

renovate 0 < 44.11.3

renovate 0 < 44.11.3

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jamietanna
.