Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updates are not subject to the internal `minimumReleaseAge` (stability age) checks. When a repository configures `minimumReleaseAge` and has dependencies with `updateType=digest` — for example GitHub Actions pinned to a commit SHA with a floating tag, Docker images, Go modules or NuGet packages — Renovate will still open a pull request for a newly published digest, marked only with a pending `renovate/stability-days` status check. A newly published, potentially malicious dependency version can therefore cause a PR to be raised and CI workflows to potentially run before the configured minimum release age has elapsed, which is precisely what the Minimum Release Age control is intended to prevent. The issue is fixed in Renovate 44.3.1; as a workaround, digest updates can be disabled or gated behind `dependencyDashboardApproval`. Join the discussion | CVE Database V5 | 09/10/2026, 13:05:34 UTC Added: 09/10/2026, 13:23:15 UTC |
0 Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the HTTP `Link` header without verifying that the target has the same origin as the configured registry. Registry credentials are attached to the request for the 'next' page, so a malicious or compromised NuGet registry can return a `Link` header pointing at an attacker-controlled server and cause Renovate to send the registry credentials to that server. Exploitation requires the remote registry to be malicious or compromised; such a registry would normally already have received the credentials on the initial request, so the issue primarily allows the credentials to be delivered to an additional, attacker-chosen host. The fix restricts pagination to the same origin; the previous behaviour can be re-enabled with the RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN option. Join the discussion | CVE Database V5 | 09/10/2026, 13:05:33 UTC Added: 09/10/2026, 13:23:12 UTC |
0 Renovate versions from 31.51.0 up to but not including 40.33.0 have a command injection vulnerability in the helmv3 manager. This vulnerability arises because the repository parameter is appended to helm registry login commands without proper sanitization. An attacker with repository write access can exploit this by crafting malicious Chart.yaml files to execute arbitrary commands on the machine running Renovate. The vulnerability has a high severity score of 8.4. Join the discussion | CVE Database V5 | 08/20/2026, 09:37:20 UTC Added: 08/19/2026, 14:23:58 UTC |
0 Renovate versions from 39.218.0 up to but not including 40.33.0 contain a command injection vulnerability in the kustomize manager. This flaw allows attackers with repository write access to execute arbitrary commands on the Renovate host by using malicious kustomization.yaml files with specially crafted chart names. The vulnerability arises because these chart names are appended unsafely to helm pull commands. It has a high severity score of 8.4. Join the discussion | CVE Database V5 | 08/20/2026, 09:37:20 UTC Added: 08/19/2026, 14:23:58 UTC |
0 Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies that are referenced in bazel mod deps calls, such as within ctx.execute statements. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:08 UTC Added: 08/19/2026, 14:23:54 UTC |
0 Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations, gaining full access to Renovate's execution environment. Join the discussion | CVE Database V5 | 08/19/2026, 14:01:49 UTC Added: 08/19/2026, 14:23:35 UTC |
Showing 1 to 6 of 6 results