GPU VulnDB

Database/Control plane, storage & DevOps

Renovate: NuGet datasource follows cross-origin Link pagination and leaks registry credentials

CVSS 9.2CVE-2026-88882Control plane, storage & DevOpscurated

Impact

The NuGet version-listing path in Renovate follows the registry-supplied Link header for the next page and attaches the configured registry credentials without a same-origin check, so a malicious or compromised NuGet registry can have those credentials delivered to a server it controls. This is the same class of bug as the Docker-datasource issue fixed in the same release but a separate advisory and a separate code path with its own feature flag. Impact for a GPU fleet is narrower - it costs you package-feed credentials, which matter mostly if the feed is an internal artifact repository shared with other build pipelines. A registry able to exploit this already received the credentials on the first request; the gain for the attacker is reaching an extra host of their choosing.

Who can reach it

An operator of a NuGet registry your Renovate instance is configured to query, or anyone who has compromised one. Unauthenticated with respect to your infrastructure - it only requires controlling a registry HTTP response.

What to do

Upgrade to Renovate 44.11.2, Mend Renovate CE/EE 15.4.0, or mend-renovate-enterprise-edition Helm chart 10.4.0 and redeploy the bot; a pod/daemon restart is enough, no node maintenance. Leave RENOVATE_X_NUGET_PAGINATION_ALLOW_CROSS_ORIGIN unset - it re-enables the old behaviour. Rotate any NuGet feed credentials Renovate was configured with.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.