<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:renovate:renovate:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3arenovaterenovate/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 15:12:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3arenovaterenovate/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Link Header Validation in Renovate</title><link>https://feed.craftedsignal.io/briefs/2026-09-renovate-link-header-vuln/</link><pubDate>Thu, 10 Sep 2026 15:12:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-renovate-link-header-vuln/</guid><description>Renovate versions prior to 44.11.3 fail to validate Link header destinations during GitLab server pagination, enabling attackers to exfiltrate credentials via malicious redirects.</description><content:encoded><![CDATA[<p>Renovate versions prior to 44.11.3 contain a vulnerability (CVE-2026-88880) related to the improper handling of 'Link' headers during GitLab server pagination. When Renovate follows pagination links provided by a GitLab server, it fails to sufficiently validate the destination URL. An attacker who has compromised or controls a GitLab instance can supply a malicious 'Link' header that redirects the Renovate service to attacker-controlled infrastructure. Because the requests initiated by Renovate may contain sensitive authentication credentials intended for the GitLab API, this redirection can result in the exfiltration of those credentials. This vulnerability poses a significant risk to CI/CD pipelines where Renovate is used to automate dependency updates, as successful exploitation allows for credential theft and potential lateral movement into the organization's software supply chain.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-88880 leads to the exfiltration of sensitive authentication credentials stored within or utilized by the Renovate service. This can result in unauthorized access to internal GitLab repositories, dependency management configurations, and broader CI/CD pipeline infrastructure, potentially facilitating code tampering or further downstream supply chain attacks.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Renovate to version 44.11.3 or later immediately to patch CVE-2026-88880.</li>
<li>Audit logs for outbound connections from the Renovate service to unexpected or newly registered domains, particularly following interactions with self-hosted or untrusted GitLab instances.</li>
<li>Review GitLab server configurations and repository settings to ensure that only authorized and secure instances are interacting with the organization's automation tools.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>vulnerability</category><category>renovate</category><category>gitlab</category></item></channel></rss>