Known Vulnerabilities for Renovate by Renovatebot
Listed below are 10 of the newest known vulnerabilities associated with "Renovate" by "Renovatebot".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-88889 json | Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to exec... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88888 json | Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies wi... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88887 json | Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88886 json | Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before ... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88885 json | Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName par... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88884 json | Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, men... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88883 json | Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88882 json | Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88881 json | Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when int... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88880 json | Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing maliciou... | Not Provided | 2026-09-10 | 2026-09-10 |