Database/Control plane, storage & DevOps
Renovate: NuGet datasource follows cross-origin Link pagination and leaks registry credentials
Impact
The NuGet version-listing path in Renovate follows the registry-supplied Link header for the next page and attaches the configured registry credentials without a same-origin check, so a malicious or compromised NuGet registry can have those credentials delivered to a server it controls. This is the same class of bug as the Docker-datasource issue fixed in the same release but a separate advisory and a separate code path with its own feature flag. Impact for a GPU fleet is narrower - it costs you package-feed credentials, which matter mostly if the feed is an internal artifact repository shared with other build pipelines. A registry able to exploit this already received the credentials on the first request; the gain for the attacker is reaching an extra host of their choosing.
Who can reach it
An operator of a NuGet registry your Renovate instance is configured to query, or anyone who has compromised one. Unauthenticated with respect to your infrastructure - it only requires controlling a registry HTTP response.
What to do
Upgrade to Renovate 44.11.2, Mend Renovate CE/EE 15.4.0, or mend-renovate-enterprise-edition Helm chart 10.4.0 and redeploy the bot; a pod/daemon restart is enough, no node maintenance. Leave RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN unset - it re-enables the old behaviour. Rotate any NuGet feed credentials Renovate was configured with.
References
Related entries
- Renovate: Docker datasource follows cross-origin Link pagination and sends registry credentials to the attacker's hostCVE-2026-88887 · Renovate (container/Docker datasource registry pagination)Critical
- Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who canCVE-2017-16727 · Moxa NPort W2150A / W2250A wireless device serverCritical
- Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitiveCVE-2018-6440 · Brocade Fabric OS (proxy service information disclosure)Critical
- IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1: Unauthorized access to user data, or injection ofCVE-2020-4926 · IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1Critical
- Cisco APIC / Cloud APIC (API endpoint): Unauthenticated arbitrary file read and write on the APICCVE-2021-1577 · Cisco APIC / Cloud APIC (API endpoint)Critical
- Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: Path traversal to remote code executionCVE-2021-22794 · Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and priorCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.