Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode. Join the discussion | CVE Database V5 | 09/10/2026, 13:05:38 UTC Added: 09/10/2026, 13:23:15 UTC |
0 Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the original registry. A malicious or compromised container registry can therefore specify a Link header pointing to an attacker-controlled host and receive the credentials Renovate uses for that registry. Exploitation requires that the target has container (Docker) dependencies and is already interacting with the malicious or compromised registry. This is fixed in Renovate 44.11.2 (npm and renovate/renovate images), Mend Renovate CE/EE 15.4.0 and the mend-renovate-enterprise-edition Helm chart 10.4.0; the same-origin check can be disabled with RENOVATE_X_DOCKER_PAGINATION_ALLOW_CROSS_ORIGIN. Join the discussion | CVE Database V5 | 09/10/2026, 13:05:36 UTC Added: 09/10/2026, 13:23:15 UTC |
0 Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module does not escape the distributionUrl value read from a repository's gradle/wrapper/gradle-wrapper.properties file before invoking the Gradle Wrapper CLI. In self-hosted deployments configured with binarySource=docker and allowedUnsafeExecutions=['gradleWrapper', ...], a repository that supplies a crafted distributionUrl (for example, appending a shell metacharacter and command) can cause arbitrary commands to be executed as the Renovate user when Renovate processes a Gradle Wrapper update. The issue is fixed in Renovate 44.14.7; as a workaround, remove 'gradleWrapper' from allowedUnsafeExecutions. Join the discussion | CVE Database V5 | 09/10/2026, 13:05:36 UTC Added: 09/10/2026, 13:23:15 UTC |
0 Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters through malicious dependency names to execute arbitrary commands as the Renovate user during Go module major version updates with postUpdateOptions gomodUpdateImportPaths enabled. Join the discussion | CVE Database V5 | 09/10/2026, 13:05:35 UTC Added: 09/10/2026, 13:23:15 UTC |
0 Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials configured for that host to the URL given as the 'next' page. Because the pagination URL is not validated against the host originally contacted, a malicious or compromised GitHub server can return a `Link` header pointing to an attacker-controlled host and cause Renovate to disclose those credentials to it. Exploitation requires that the GitHub server Renovate talks to (as the repository host or as a datasource such as github-releases, github-tags, or git-refs) is already malicious or compromised. The issue is fixed in renovate 44.11.3 (npm and renovate/renovate container images), Mend Renovate CE/EE images and the mend-renovate-ce helm chart 15.4.0, and the mend-renovate-enterprise-edition helm chart 10.4.0. There is no workaround; the pre-existing RENOVATE_X_REBASE_PAGINATION_LINKS option disables the new host check and should only be used with servers that intentionally use different pagination hosts. Join the discussion | CVE Database V5 | 09/10/2026, 13:05:32 UTC Added: 09/10/2026, 13:23:12 UTC |
0 Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials. Join the discussion | CVE Database V5 | 09/10/2026, 13:05:31 UTC Added: 09/10/2026, 13:23:12 UTC |
0 Renovate versions from 39.53.0 up to but not including 40.33.0 contain a command injection vulnerability in the gleam manager. The vulnerability arises because the depName parameter is appended to gleam deps update commands without proper sanitization. An attacker with repository write access can exploit this by crafting malicious gleam.toml files to execute arbitrary commands on the machine running Renovate. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:13 UTC Added: 08/19/2026, 14:23:58 UTC |
0 Renovate versions from 32.135.0 up to but not including 40.33.0 contain a command injection vulnerability in the hermit manager. This flaw allows attackers with repository write access to execute arbitrary commands by supplying maliciously crafted dependency names. The vulnerability arises because user input is appended to install and uninstall commands without proper sanitization. The CVSS 4.0 score is 8.4, indicating high severity. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:12 UTC Added: 08/19/2026, 14:23:58 UTC |
0 Renovate versions from 35.63.0 up to but not including 40.33.0 contain a command injection vulnerability in the npm manager. This flaw allows attackers with repository write access to craft malicious Renovate configuration files that execute arbitrary commands on the host running Renovate. The vulnerability arises because user-supplied packageName values are appended to npm install commands without proper sanitization. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:11 UTC Added: 08/19/2026, 14:23:58 UTC |
0 Renovate versions from 42.68.1 before 42.96.3 and from 42.68.1 before 43.4.4, including certain Docker images and Renovate Enterprise versions 13.3.0 up to but not including 13.6.0, do not restrict environment variables when spawning child processes. This allows child processes to access all environment variables of the Renovate process, potentially exposing sensitive information to insider or external attackers. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:09 UTC Added: 08/19/2026, 14:23:58 UTC |
Showing 1 to 10 of 10 results