Skip to main content

CVE-2026-88882: URL Redirection to Untrusted Site ('Open Redirect') in renovatebot renovate

0
Critical
VulnerabilityCVE-2026-88882cvecve-2026-88882
Published: 09/10/2026 (09/10/2026, 13:05:33 UTC)
Source: CVE Database V5
Vendor/Project: renovatebot
Product: renovate

Description

Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the HTTP `Link` header without verifying that the target has the same origin as the configured registry. Registry credentials are attached to the request for the 'next' page, so a malicious or compromised NuGet registry can return a `Link` header pointing at an attacker-controlled server and cause Renovate to send the registry credentials to that server. Exploitation requires the remote registry to be malicious or compromised; such a registry would normally already have received the credentials on the initial request, so the issue primarily allows the credentials to be delivered to an additional, attacker-chosen host. The fix restricts pagination to the same origin; the previous behaviour can be re-enabled with the RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN option.

CVSS v4.0

Score 9.2critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Affected software

renovatebot

renovate

Affected versions
>=0 <44.11.2

renovatebot

renovate

Affected versions
>=0 <15.4.0

renovatebot

renovate

Affected versions
>=0 <10.4.0
GitHub Actionsmore threats →ai
renovatebot/renovate
pkg:github/renovatebot/renovate
Affected versions
<44.11.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 13:55:00 UTC

Technical Analysis

Renovate versions prior to 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0) contain an open redirect vulnerability. When listing new package versions from a NuGet registry, renovate follows pagination URLs supplied in the HTTP Link header without verifying that the target URL shares the same origin as the configured registry. Because registry credentials are attached to the request for the next page, a malicious or compromised NuGet registry can supply a Link header pointing to an attacker-controlled server, causing renovate to send credentials to that server. Exploitation requires control or compromise of the NuGet registry, which would normally already have the credentials from the initial request. The vulnerability primarily allows credentials to be leaked to an additional attacker-chosen host. The fix restricts pagination URLs to the same origin, with an option to re-enable the previous behavior via RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN.

Potential Impact

An attacker controlling or compromising a NuGet registry can cause renovate to send registry credentials to an attacker-controlled server by supplying malicious pagination URLs. This can lead to credential leakage beyond the initially compromised registry. However, since exploitation requires control of the registry, the impact is limited to credential exposure to an additional host rather than initial credential theft. The vulnerability has a high CVSS score of 9.2, indicating critical severity due to network attack vector, no required privileges or user interaction, and high impact on confidentiality.

Mitigation Recommendations

A fix is available in renovate version 44.11.2 and in Mend Renovate CE/EE images and charts version 15.4.0 and later, as well as mend-renovate-enterprise-edition helm chart version 10.4.0 and later. The fix restricts pagination URLs to the same origin as the configured NuGet registry, preventing credentials from being sent to untrusted hosts. Users should upgrade to these fixed versions. If necessary, the previous behavior allowing cross-origin pagination can be re-enabled via the RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN option, but this is not recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-10T11:25:34.912Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6aa2af40acd9273b492596ef

Added to database: 09/10/2026, 13:23:12 UTC

Last enriched: 09/10/2026, 13:55:00 UTC

Last updated: 09/10/2026, 22:12:33 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses