Security: renovatebot/renovate
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Malicious GitLab servers could send a malicious `Link` header to allow exflitrating credentialsGHSA-9hmg-9h89-jhmx published
Aug 27, 2026 by jamietannaHigh -
Malicious GitHub servers could send a malicious `Link` header to allow exflitrating credentialsGHSA-w57v-h33h-835c published
Aug 27, 2026 by jamietannaHigh -
Malicious Nuget registries could send a malicious `Link` header to allow exflitrating credentialsGHSA-rh7w-ccch-gh49 published
Aug 27, 2026 by jamietannaHigh -
TLS private keys were previously not sanitised in logsGHSA-4hmw-qw74-vrhm published
Aug 27, 2026 by jamietannaHigh -
Digest updates can bypass strict `minimumReleaseAge` internal checksGHSA-g4qr-hw2h-687r published
Aug 27, 2026 by jamietannaModerate -
`manager/gomod`: Command injection could be possible via unescaped `depName` in import-path update commandGHSA-mpf8-qxrw-gq3w published
Aug 27, 2026 by jamietannaHigh -
`manager/gradle-wrapper`: Command injection could be possible via unescaped `distributionUrl`GHSA-7chm-46wx-888m published
Aug 27, 2026 by jamietannaHigh -
Malicious Docker registries could send a malicious `Link` header to allow exflitrating credentialsGHSA-v73q-hvqx-hxwx published
Aug 27, 2026 by jamietannaHigh -
`manager/mix`: Command injection could be possible via unescaped `organization`GHSA-v85g-rq5w-c46q published
Aug 27, 2026 by jamietannaHigh -
`manager/maven-wrapper`: Command injection could be possible via unescaped `distributionType`GHSA-f2v7-35mm-3hx7 published
Aug 27, 2026 by jamietannaHigh