CVE-2026-88887: Renovate before 44.11.2 Credential Exfiltration via Link Header

Published Sep 10, 2026
·
Updated

Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the original registry. A malicious or compromised container registry can therefore specify a Link header pointing to an attacker-controlled host and receive the credentials Renovate uses for that registry. Exploitation requires that the target has container (Docker) dependencies and is already interacting with the malicious or compromised registry. This is fixed in Renovate 44.11.2 (npm and renovate/renovate images), Mend Renovate CE/EE 15.4.0 and the mend-renovate-enterprise-edition Helm chart 10.4.0; the same-origin check can be disabled with RENOVATEXDOCKERPAGINATIONALLOWCROSSORIGIN.

Affected Software

4 affected components
npm/renovate<44.11.2
npm/renovate/renovate<44.11.2
Mend Mend Renovate CE/EE<15.4.0
Mend mend-renovate-enterprise-edition<10.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Renovate (npm and renovate/renovate images) to a version that resolves this vulnerability.

    Fixed in 44.11.2
  2. Upgrade

    Upgrade Mend Renovate CE/EE to a version that resolves this vulnerability.

    Fixed in 15.4.0
  3. Upgrade

    Upgrade mend-renovate-enterprise-edition Helm chart to a version that resolves this vulnerability.

    Fixed in 10.4.0
  4. Configuration

    Ensure RENOVATE_X_DOCKER_PAGINATION_ALLOW_CROSS_ORIGIN is not enabled so the same-origin check is not disabled.

    Renovate RENOVATE_X_DOCKER_PAGINATION_ALLOW_CROSS_ORIGIN = disable / do not allow cross-origin

Event History

Sep 10, 2026
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which environments are exposed to credential exfiltration?

Exposure requires Renovate to process container (Docker) dependencies and interact with a malicious or compromised container registry. The registry can provide a pagination Link header that directs Renovate to an attacker-controlled host.

2

What credentials could be disclosed?

The attacker-controlled host can receive the credentials that Renovate uses for the affected registry, because those credentials are attached to the pagination follow-up request.

3

Which fixed releases are available?

The issue is fixed in Renovate 44.11.2 for npm and renovate/renovate images, Mend Renovate CE/EE 15.4.0, and mend-renovate-enterprise-edition Helm chart 10.4.0.

4

Is there a configuration that can re-enable the vulnerable behavior?

Yes. RENOVATE_X_DOCKER_PAGINATION_ALLOW_CROSS_ORIGIN disables the same-origin check for Docker pagination, which permits cross-origin pagination requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203