CVE-2026-88882: Renovate before 44.11.2 Credential Exfiltration via Link Header

Published Sep 10, 2026
·
Updated

Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the HTTP Link header without verifying that the target has the same origin as the configured registry. Registry credentials are attached to the request for the 'next' page, so a malicious or compromised NuGet registry can return a Link header pointing at an attacker-controlled server and cause Renovate to send the registry credentials to that server. Exploitation requires the remote registry to be malicious or compromised; such a registry would normally already have received the credentials on the initial request, so the issue primarily allows the credentials to be delivered to an additional, attacker-chosen host. The fix restricts pagination to the same origin; the previous behaviour can be re-enabled with the RENOVATEXNUGETPAGINATIONALLOWCROSSORIGIN option.

Affected Software

3 affected components
Renovate<44.11.2
Mend Renovate CE/EE (images and charts)<15.4.0
mend-renovate-enterprise-edition (Helm chart)<10.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Renovate to a version that resolves this vulnerability.

    Fixed in 44.11.2
  2. Upgrade

    Upgrade Mend Renovate CE/EE images and charts to a version that resolves this vulnerability.

    Fixed in 15.4.0
  3. Upgrade

    Upgrade mend-renovate-enterprise-edition helm chart to a version that resolves this vulnerability.

    Fixed in 10.4.0
  4. Configuration

    Keep RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN unset/disabled so Renovate restricts NuGet pagination URLs to the same origin as the configured registry (prevent credentials from being sent to attacker-controlled hosts via the HTTP Link header).

    Renovate RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN = disabled

Event History

Sep 10, 2026
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue in practice?

Exploitation requires a NuGet registry that is malicious or has been compromised. The registry must return a pagination URL in an HTTP Link header that points to an attacker-controlled host.

2

What credentials are exposed, and what is the impact?

Renovate can attach the configured NuGet registry credentials when requesting the attacker-controlled next-page URL. Because the registry normally receives those credentials on the initial request already, the primary additional impact is disclosure of them to another host selected by the attacker.

3

Which versions contain the fix?

The fix is in Renovate 44.11.2, Mend Renovate CE/EE images and charts 15.4.0, and the mend-renovate-enterprise-edition Helm chart 10.4.0. Earlier versions are affected.

4

Can the unsafe behavior be enabled after updating?

Yes. Setting RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN re-enables cross-origin NuGet pagination behavior that the fix otherwise restricts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203