{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/renovate--44.11.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mend:renovate:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-88881"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Renovate (\u003c 44.11.3)","Mend Renovate CE/EE (\u003c 15.4.0)","Mend Renovate Enterprise Edition (\u003c 10.4.0)","Renovate (\u003c 44.11.2)","mend-renovate-enterprise-edition (\u003c 10.4.0)","mend-renovate-enterprise-edition Helm chart (\u003c 10.4.0)"],"_cs_severities":["high"],"_cs_tags":["credential-access","supply-chain","vulnerability","supply-chain-security","credential-theft","nuget","dependency-management"],"_cs_type":"advisory","_cs_vendors":["Mend"],"content_html":"\u003cp\u003eRenovate, a widely used dependency update tool, contains a vulnerability (CVE-2026-88881) where it fails to validate the hostname of pagination links provided in HTTP 'Link' headers when interacting with GitHub-compatible servers. Under normal operation, Renovate follows 'next' page links provided by the server to traverse API results. However, if a GitHub-compatible server (repository host or datasource) is compromised or controlled by an attacker, it can supply a 'next' link pointing to an arbitrary, attacker-controlled domain. Renovate will subsequently send its configured credentials for the original host to this malicious destination. This impacts organizations using Renovate versions prior to 44.11.3, as well as Mend Renovate CE/EE and Enterprise Edition versions 15.4.0 and 10.4.0 respectively. There is no configuration-based workaround; the existing RENOVATE_X_REBASE_PAGINATION_LINKS option serves to disable the new host check and should not be used as a mitigation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk of credential theft, specifically targeting the tokens or credentials configured within the Renovate instance to authenticate against GitHub or GitHub-compatible infrastructure. If exploited, an attacker could capture these credentials and leverage them to access private repositories, modify code, or perform unauthorized administrative actions within the victim's GitHub environment. This affects all sectors relying on automated dependency management through Renovate.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Renovate npm package and container images to 44.11.3 or later immediately.\u003c/li\u003e\n\u003cli\u003eUpgrade Mend Renovate CE/EE helm chart to 15.4.0 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade Mend Renovate Enterprise Edition helm chart to 10.4.0 or later.\u003c/li\u003e\n\u003cli\u003eReview access logs and outbound network traffic originating from Renovate runners for connections to unexpected or unauthorized domains following GitHub API interactions.\u003c/li\u003e\n\u003cli\u003eEnsure that the RENOVATE_X_REBASE_PAGINATION_LINKS environment variable is not set to true, as it explicitly disables host validation.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-10T15:15:39Z","date_published":"2026-09-10T15:14:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-renovate-credential-leak/","summary":"Renovate improperly validates HTTP 'Link' headers during GitHub API interactions, allowing a compromised GitHub server to exfiltrate configured credentials by redirecting pagination requests to an attacker-controlled host.","title":"Credential Disclosure in Renovate via Malicious Pagination Links","url":"https://feed.craftedsignal.io/briefs/2026-09-renovate-credential-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Renovate (\u003c 44.11.2)","version":"https://jsonfeed.org/version/1.1"}