CVE-2026-88880: Renovate before 44.11.3 Credential Exfiltration via Link Header
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Renovate deployments that interact with a compromised or malicious GitLab server are exposed, because the server can control pagination Link headers returned to Renovate.
What does an attacker need to exploit it?
The attacker needs control of a GitLab server used by Renovate, or must compromise such a server. They can then provide a pagination Link header that directs Renovate to attacker-controlled infrastructure.
What is the impact of successful exploitation?
Renovate can send credential-bearing requests to attacker-controlled infrastructure, allowing authentication credentials to be exfiltrated.
What version resolves the issue?
The issue affects Renovate versions before 44.11.3. Upgrade to 44.11.3 or later.