CVE-2026-88882: URL Redirection to Untrusted Site ('Open Redirect') in renovatebot renovate
Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the HTTP `Link` header without verifying that the target has the same origin as the configured registry. Registry credentials are attached to the request for the 'next' page, so a malicious or compromised NuGet registry can return a `Link` header pointing at an attacker-controlled server and cause Renovate to send the registry credentials to that server. Exploitation requires the remote registry to be malicious or compromised; such a registry would normally already have received the credentials on the initial request, so the issue primarily allows the credentials to be delivered to an additional, attacker-chosen host. The fix restricts pagination to the same origin; the previous behaviour can be re-enabled with the RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN option.
AI Analysis
Technical Summary
Renovate versions prior to 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0) contain an open redirect vulnerability. When listing new package versions from a NuGet registry, renovate follows pagination URLs supplied in the HTTP Link header without verifying that the target URL shares the same origin as the configured registry. Because registry credentials are attached to the request for the next page, a malicious or compromised NuGet registry can supply a Link header pointing to an attacker-controlled server, causing renovate to send credentials to that server. Exploitation requires control or compromise of the NuGet registry, which would normally already have the credentials from the initial request. The vulnerability primarily allows credentials to be leaked to an additional attacker-chosen host. The fix restricts pagination URLs to the same origin, with an option to re-enable the previous behavior via RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN.
Potential Impact
An attacker controlling or compromising a NuGet registry can cause renovate to send registry credentials to an attacker-controlled server by supplying malicious pagination URLs. This can lead to credential leakage beyond the initially compromised registry. However, since exploitation requires control of the registry, the impact is limited to credential exposure to an additional host rather than initial credential theft. The vulnerability has a high CVSS score of 9.2, indicating critical severity due to network attack vector, no required privileges or user interaction, and high impact on confidentiality.
Mitigation Recommendations
A fix is available in renovate version 44.11.2 and in Mend Renovate CE/EE images and charts version 15.4.0 and later, as well as mend-renovate-enterprise-edition helm chart version 10.4.0 and later. The fix restricts pagination URLs to the same origin as the configured NuGet registry, preventing credentials from being sent to untrusted hosts. Users should upgrade to these fixed versions. If necessary, the previous behavior allowing cross-origin pagination can be re-enabled via the RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN option, but this is not recommended.
CVE-2026-88882: URL Redirection to Untrusted Site ('Open Redirect') in renovatebot renovate
Description
Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the HTTP `Link` header without verifying that the target has the same origin as the configured registry. Registry credentials are attached to the request for the 'next' page, so a malicious or compromised NuGet registry can return a `Link` header pointing at an attacker-controlled server and cause Renovate to send the registry credentials to that server. Exploitation requires the remote registry to be malicious or compromised; such a registry would normally already have received the credentials on the initial request, so the issue primarily allows the credentials to be delivered to an additional, attacker-chosen host. The fix restricts pagination to the same origin; the previous behaviour can be re-enabled with the RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN option.
CVSS v4.0
Score 9.2critical
Affected software
renovatebot
renovate
renovatebot
renovate
renovatebot
renovate
pkg:github/renovatebot/renovateRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Renovate versions prior to 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0) contain an open redirect vulnerability. When listing new package versions from a NuGet registry, renovate follows pagination URLs supplied in the HTTP Link header without verifying that the target URL shares the same origin as the configured registry. Because registry credentials are attached to the request for the next page, a malicious or compromised NuGet registry can supply a Link header pointing to an attacker-controlled server, causing renovate to send credentials to that server. Exploitation requires control or compromise of the NuGet registry, which would normally already have the credentials from the initial request. The vulnerability primarily allows credentials to be leaked to an additional attacker-chosen host. The fix restricts pagination URLs to the same origin, with an option to re-enable the previous behavior via RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN.
Potential Impact
An attacker controlling or compromising a NuGet registry can cause renovate to send registry credentials to an attacker-controlled server by supplying malicious pagination URLs. This can lead to credential leakage beyond the initially compromised registry. However, since exploitation requires control of the registry, the impact is limited to credential exposure to an additional host rather than initial credential theft. The vulnerability has a high CVSS score of 9.2, indicating critical severity due to network attack vector, no required privileges or user interaction, and high impact on confidentiality.
Mitigation Recommendations
A fix is available in renovate version 44.11.2 and in Mend Renovate CE/EE images and charts version 15.4.0 and later, as well as mend-renovate-enterprise-edition helm chart version 10.4.0 and later. The fix restricts pagination URLs to the same origin as the configured NuGet registry, preventing credentials from being sent to untrusted hosts. Users should upgrade to these fixed versions. If necessary, the previous behavior allowing cross-origin pagination can be re-enabled via the RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN option, but this is not recommended.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-10T11:25:34.912Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa2af40acd9273b492596ef
Added to database: 09/10/2026, 13:23:12 UTC
Last enriched: 09/10/2026, 13:55:00 UTC
Last updated: 09/10/2026, 22:12:33 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.