CVE-2026-88883: Renovate before 44.14.4 TLS Private Key Log Sanitisation

Published Sep 10, 2026
·
Updated

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].httpsPrivateKey was redacted in the field itself, the same private key value was not redacted if it also appeared elsewhere — for example in another configuration option or in a log message under a key other than httpsPrivateKey — causing the full private key to be written to Renovate's logs in cleartext. This affects deployments that configure Mutual TLS through hostRules[].httpsPrivateKey without passing the value through the documented secrets configuration. Anyone able to read the resulting logs can recover the private key. The issue is fixed in Renovate 44.14.4, which redacts any value supplied as hostRules[].httpsPrivateKey wherever it appears in the logs; as a workaround, supply the key via the secrets configuration.

Affected Software

3 affected components
Renovate<44.14.4
Mend Renovate CE/EE images<15.4.0
mend-renovate-enterprise-edition Helm chart<10.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Renovate to a version that resolves this vulnerability.

    Fixed in 44.14.4
  2. Configuration

    As a workaround for versions before 44.14.4 (and before 15.4.0 for Mend Renovate CE/EE images, and before 10.4.0 for the mend-renovate-enterprise-edition Helm chart), supply the Mutual TLS private key via the documented `secrets` configuration rather than passing it directly in `hostRules[].httpsPrivateKey`.

    Renovate secrets = Provide TLS Private Key for Mutual TLS via `secrets` configuration instead of `hostRules[].httpsPrivateKey`

Event History

Sep 10, 2026
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to private-key disclosure?

Deployments are affected if they configure Mutual TLS with hostRules[].httpsPrivateKey and provide that value directly rather than through the documented secrets configuration. The affected versions are Renovate before 44.14.4, Mend Renovate CE/EE images before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0.

2

What access does an attacker need to obtain the private key?

An attacker needs the ability to read Renovate logs that contain the unredacted key value. No further interaction is required once the private key has been written to the logs.

3

What can be done if upgrading is not immediately possible?

Supply the Mutual TLS private key through the documented secrets configuration rather than directly in hostRules[].httpsPrivateKey. Restrict access to existing Renovate logs, because previously generated logs may already contain the key in cleartext.

4

How can I determine whether a key may have been exposed already?

Review Renovate logs from affected deployments for the TLS private-key value appearing under configuration fields or log keys other than httpsPrivateKey. If the key was configured directly and is found in logs, treat it as recoverable by anyone who could read those logs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203