Impact
The vulnerability is a flaw where the application follows pagination links supplied by the server in the HTTP Link header without validating the host, resulting in credentials being sent to an attacker‑controlled host. This leads to credential exfiltration. The weakness is CWE‑601.
Affected Systems
The issue affects Renovate versions prior to 44.11.3, including npm packages and container images, as well as Mend Renovate CE/EE images and the mend‑renovate‑ce helm chart 15.4.0 and the mend‑renovate‑enterprise‑edition helm chart 10.4.0. It applies when Renovate interacts with GitHub.com, GitHub Enterprise Cloud or GitHub Enterprise Server.
Risk and Exploitability
The CVSS score of 9.2 indicates a severe risk, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the GitHub server Renovate connects to is already malicious or has been compromised; the attacker must supply a Link header that points to an attacker‑controlled host. If such a compromised host is used, credentials configured for the host will be transmitted, exposing authentication tokens.
OpenCVE Enrichment