Description
Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].httpsPrivateKey was redacted in the field itself, the same private key value was not redacted if it also appeared elsewhere — for example in another configuration option or in a log message under a key other than httpsPrivateKey — causing the full private key to be written to Renovate's logs in cleartext. This affects deployments that configure Mutual TLS through hostRules[].httpsPrivateKey without passing the value through the documented `secrets` configuration. Anyone able to read the resulting logs can recover the private key. The issue is fixed in Renovate 44.14.4, which redacts any value supplied as hostRules[].httpsPrivateKey wherever it appears in the logs; as a workaround, supply the key via the `secrets` configuration.
Published: 2026-09-10
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Log Exposure of Private TLS Keys
Action: Update
AI Analysis

Impact

The vulnerability allows an actor with read access to Renovate logs to retrieve TLS private keys that are used for mutual authentication. The implementation flaw results in incomplete redaction of the hostRules[].httpsPrivateKey value when it is referenced elsewhere in configuration or log messages, leaving the full key in plaintext. The exposed key could be used to impersonate the service, gain unauthorized access, or compromise future connections. This flaw is a classic example of log injection and improper sanitisation, corresponding to CWE-532.

Affected Systems

The affected product is Renovate, the automated dependency update tool produced by renovatebot. Versions earlier than 44.14.4 are impacted, as are Mend‑Renovate CE/EE Docker images below version 15.4.0 and the mend-renovate‑enterprise‑edition Helm chart prior to 10.4.0. Any deployment that configures the httpsPrivateKey in hostRules[].httpsPrivateKey without delivering it through the documented secrets configuration is vulnerable.

Risk and Exploitability

The CVSS score of 8.3 indicates a high impact. The EPSS score of 0.28 % shows a very low probability of exploitation in the wild and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation. The attack requires read access to the Renovate logs; an attacker who can read these logs could extract the TLS private key and use it to impersonate the service or establish unauthorized TLS connections. Therefore, while the technical impact is severe, the likelihood of exploitation is currently very low but patching remains recommended.

Generated by OpenCVE AI on September 21, 2026 at 05:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Renovate to version 44.14.4 or later, and update Mend Renovate images to 15.4.0 or later and Helm chart to 10.4.0 or later.
  • If immediate upgrade is not possible, configure TLS private keys through the secrets configuration instead of hostRules[].httpsPrivateKey to trigger proper log sanitisation.
  • Restrict read access to Renovate log files and ensure that logs do not expose private key material; periodically audit logs for unintended key disclosure.

Generated by OpenCVE AI on September 21, 2026 at 05:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-117
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Renovatebot
Renovatebot renovate
Vendors & Products Renovatebot
Renovatebot renovate

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].httpsPrivateKey was redacted in the field itself, the same private key value was not redacted if it also appeared elsewhere — for example in another configuration option or in a log message under a key other than httpsPrivateKey — causing the full private key to be written to Renovate's logs in cleartext. This affects deployments that configure Mutual TLS through hostRules[].httpsPrivateKey without passing the value through the documented `secrets` configuration. Anyone able to read the resulting logs can recover the private key. The issue is fixed in Renovate 44.14.4, which redacts any value supplied as hostRules[].httpsPrivateKey wherever it appears in the logs; as a workaround, supply the key via the `secrets` configuration.
Title Renovate before 44.14.4 TLS Private Key Log Sanitisation
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Renovatebot Renovate
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-29T22:10:39.458Z

Reserved: 2026-09-10T11:25:34.912Z

Link: CVE-2026-88883

cve-icon Vulnrichment

Updated: 2026-09-10T14:18:27.262Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T14:17:16.997

Modified: 2026-09-29T23:17:23.790

Link: CVE-2026-88883

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T13:05:33Z

Links: CVE-2026-88883 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:45:10Z

Weaknesses
  • CWE-117

    Improper Output Neutralization for Logs

  • CWE-532

    Insertion of Sensitive Information into Log File