CVE-2026-88880
Undergoing Analysis Undergoing Analysis - In Progress

Renovate GitLab Pagination Link Header Redirect Vulnerability

Vulnerability report for CVE-2026-88880, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
renovatebot renovate to 44.11.3 (exc)
renovatebot renovate From 0 (inc) to 44.11.3 (exc)
renovatebot renovate From 0.15.4 (inc) to 44.11.3 (exc)
renovatebot renovate From 0.10.4 (inc) to 44.11.3 (exc)
renovatebot renovate 44.11.2
renovatebot renovate 15.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Renovate before version 44.11.3 fails to validate Link header destinations when following GitLab server pagination. This allows malicious GitLab servers to redirect credential-bearing requests to attacker-controlled infrastructure, potentially stealing authentication credentials.

Detection Guidance

Check Renovate version with 'renovate --version'. If it's below 44.11.3, the system is vulnerable. Monitor network traffic for unexpected outbound connections to GitLab servers during Renovate operations.

Impact Analysis

If you use Renovate versions before 44.11.3 and interact with a compromised GitLab server, attackers could exfiltrate your authentication credentials. This happens automatically without user interaction or privileges, posing a high risk of unauthorized access to your systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations may face compliance breaches if credentials are stolen and used to access protected data.

Mitigation Strategies

Upgrade Renovate to version 44.11.3 or later immediately. If using enterprise editions, upgrade to 15.4.0 or later. No workarounds exist; patching is required to prevent credential exfiltration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88880. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart