Retour à la veille

CVE-2026-88880

Publié : 10 septembre 2026
Modifié : 10 septembre 2026
Lien officiel NVD
Score CVSS
8.6
HIGH

Description détaillée

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Références et Patchs