CVE-2026-88880

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.

Scoring

Severity
CRITICAL
CVSS base score
9.2
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CWE
CWE-601
Published
2026-09-10
Last modified
2026-09-10

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs