Junglewise Threat Intelligence

CVE-2026-88882: Renovate NuGet credential exfiltration via Link header

CVE-2026-88882 · Severity: high · CVSS 8.6 · Published 2026-09-10

Technologies: Renovate, Mend Renovate-Ee-Server, Mend Renovate-Ce, Mend Renovate-Ee-Worker. Vendors: Mend.

Executive brief

Renovate is a dependency update automation tool used to keep software dependencies current. When querying NuGet registries for package updates, Renovate blindly follows pagination links in HTTP headers without verifying they point to the legitimate registry. A malicious or compromised NuGet registry can exploit this to redirect credential-bearing requests to an attacker-controlled server, exposing registry credentials. While the registry typically has credentials from the initial request, this vulnerability allows an attacker to harvest credentials on a secondary target.

Technical details

This vulnerability is an open redirect / cross-origin credential leak in Renovate's NuGet registry pagination logic. When Renovate pages through search results from a NuGet registry, it follows the `Link` HTTP header provided by the remote registry without validating that the pagination URL has the same origin as the configured registry. Since authentication credentials are attached to all requests to the registry, an attacker controlling or compromising a NuGet registry can craft a malicious `Link` header pointing to an attacker-controlled server, causing Renovate to send the registry credentials to that server. Exploitation requires the NuGet registry itself to be compromised or malicious; no user interaction or authentication is needed. The vulnerability has been fixed in Renovate 44.11.2 and Mend CE/EE versions 15.4.0 and 10.4.0, which now restrict pagination to the same origin. The previous behavior can be re-enabled via the RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN option.

Affected products

  • Renovate Renovate before 44.11.2
  • Mend Renovate CE before 15.4.0
  • Mend Renovate EE Server before 15.4.0
  • Mend Renovate EE Worker before 15.4.0
  • Mend mend-renovate-enterprise-edition before 10.4.0

Timeline

  • 2026-08-27: disclosed: Security advisory GHSA-rh7w-ccch-gh49 published
  • 2026-09-10: patched: Renovate 44.11.2, Mend CE/EE 15.4.0, and mend-renovate-enterprise-edition 10.4.0 released with fix

References

Related threats