Database/Control plane, storage & DevOps
Renovate: unvalidated GitLab Link header redirects credential-bearing pagination requests
Impact
The GitLab pagination path in Renovate does not validate the destination of the Link header before following it, so a compromised GitLab server can redirect a credential-bearing request to attacker infrastructure and capture the token configured for that host. This is the GitLab counterpart of CVE-2026-88881 and carries its own advisory; both are fixed in 44.11.3. Where a fleet's infrastructure-as-code lives in self-hosted GitLab, the leaked token usually carries write access to the repositories that pin driver, firmware and Kubernetes manifest versions, which turns a credential leak into influence over what lands on GPU nodes. Exploitation depends on the GitLab server already being malicious or compromised.
Who can reach it
Requires control of the GitLab server Renovate contacts; from there it is unauthenticated and remote. No access to the machine running Renovate is needed.
What to do
Upgrade Renovate to 44.11.3 - a container image or npm package bump and redeploy of the bot, with no GPU node impact. Rotate GitLab tokens that Renovate presented to any server you cannot vouch for. The record does not describe a workaround for the GitLab path.
References
Related entries
- Renovate: unvalidated GitHub Link header sends host credentials to an attacker-controlled serverCVE-2026-88881 · Renovate (GitHub pagination, HTTP Link header host validation)Critical
- Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who canCVE-2017-16727 · Moxa NPort W2150A / W2250A wireless device serverCritical
- Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitiveCVE-2018-6440 · Brocade Fabric OS (proxy service information disclosure)Critical
- IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1: Unauthorized access to user data, or injection ofCVE-2020-4926 · IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1Critical
- Cisco APIC / Cloud APIC (API endpoint): Unauthenticated arbitrary file read and write on the APICCVE-2021-1577 · Cisco APIC / Cloud APIC (API endpoint)Critical
- Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: Path traversal to remote code executionCVE-2021-22794 · Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and priorCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.