{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/renovate--44.14.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:renovate:renovate:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-88880"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Renovate (\u003c 44.11.3)","Renovate (\u003c 44.14.7)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","vulnerability","renovate","gitlab"],"_cs_type":"advisory","_cs_vendors":["Renovate"],"content_html":"\u003cp\u003eRenovate versions prior to 44.11.3 contain a vulnerability (CVE-2026-88880) related to the improper handling of 'Link' headers during GitLab server pagination. When Renovate follows pagination links provided by a GitLab server, it fails to sufficiently validate the destination URL. An attacker who has compromised or controls a GitLab instance can supply a malicious 'Link' header that redirects the Renovate service to attacker-controlled infrastructure. Because the requests initiated by Renovate may contain sensitive authentication credentials intended for the GitLab API, this redirection can result in the exfiltration of those credentials. This vulnerability poses a significant risk to CI/CD pipelines where Renovate is used to automate dependency updates, as successful exploitation allows for credential theft and potential lateral movement into the organization's software supply chain.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-88880 leads to the exfiltration of sensitive authentication credentials stored within or utilized by the Renovate service. This can result in unauthorized access to internal GitLab repositories, dependency management configurations, and broader CI/CD pipeline infrastructure, potentially facilitating code tampering or further downstream supply chain attacks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Renovate to version 44.11.3 or later immediately to patch CVE-2026-88880.\u003c/li\u003e\n\u003cli\u003eAudit logs for outbound connections from the Renovate service to unexpected or newly registered domains, particularly following interactions with self-hosted or untrusted GitLab instances.\u003c/li\u003e\n\u003cli\u003eReview GitLab server configurations and repository settings to ensure that only authorized and secure instances are interacting with the organization's automation tools.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T15:15:28Z","date_published":"2026-09-10T15:12:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-renovate-link-header-vuln/","summary":"Renovate versions prior to 44.11.3 fail to validate Link header destinations during GitLab server pagination, enabling attackers to exfiltrate credentials via malicious redirects.","title":"Improper Link Header Validation in Renovate","url":"https://feed.craftedsignal.io/briefs/2026-09-renovate-link-header-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Renovate (\u003c 44.14.7)","version":"https://jsonfeed.org/version/1.1"}