CVE-2026-88880
HIGH
NVD
CVSS Score
8.6
Severity
HIGH
Published
Sep 10, 2026
Vendor
unknown
Description
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.