---
id: CVE-2026-88880
title: >-
  Renovate before 44.11.3 fails to validate Link header destinations when
  following GitLab server pagination, allowing malicious servers to redirect
  credential-bearing requests
summary: >-
  Renovate before 44.11.3 fails to validate Link header destinations when
  following GitLab server pagination, allowing malicious servers to redirect
  credential-bearing requests. Attackers controlling a compromised GitLab server
  can specify…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-601
vendor: renovatebot
product: renovate
affected:
  - renovate < 44.11.3
  - renovate < 44.11.3
  - renovate < 44.11.3
  - renovate < 44.11.3
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 10.4.0
  - renovate < 10.4.0
published: '2026-09-10'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:37.990'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88880'
references:
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-9hmg-9h89-jhmx
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/renovate-before-44.11.3-credential-exfiltration-via-link-header
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00504
epssPercentile: 0.40423
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-18T17:11:40.160815Z'
ingestedAt: '2026-09-14T04:32:23.072Z'
---

## Overview

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
