GPU VulnDB

Database/Control plane, storage & DevOps

Renovate: unvalidated GitLab Link header redirects credential-bearing pagination requests

CVSS 9.2CVE-2026-88880Control plane, storage & DevOpscurated

Impact

The GitLab pagination path in Renovate does not validate the destination of the Link header before following it, so a compromised GitLab server can redirect a credential-bearing request to attacker infrastructure and capture the token configured for that host. This is the GitLab counterpart of CVE-2026-88881 and carries its own advisory; both are fixed in 44.11.3. Where a fleet's infrastructure-as-code lives in self-hosted GitLab, the leaked token usually carries write access to the repositories that pin driver, firmware and Kubernetes manifest versions, which turns a credential leak into influence over what lands on GPU nodes. Exploitation depends on the GitLab server already being malicious or compromised.

Who can reach it

Requires control of the GitLab server Renovate contacts; from there it is unauthenticated and remote. No access to the machine running Renovate is needed.

What to do

Upgrade Renovate to 44.11.3 - a container image or npm package bump and redeploy of the bot, with no GPU node impact. Rotate GitLab tokens that Renovate presented to any server you cannot vouch for. The record does not describe a workaround for the GitLab path.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.