CVE-2026-88884
Last modified
CVE-2026-88884 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updates are not subject to the internal `minimumReleaseAge` (stability age) checks.
Description
Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updates are not subject to the internal `minimumReleaseAge` (stability age) checks. When a repository configures `minimumReleaseAge` and has dependencies with `updateType=digest` — for example GitHub Actions pinned to a commit SHA with a floating tag, Docker images, Go modules or NuGet packages — Renovate will still open a pull request for a newly published digest, marked only with a pending `renovate/stability-days` status check. A newly published, potentially malicious dependency version can therefore cause a PR to be raised and CI workflows to potentially run before the configured minimum release age has elapsed, which is precisely what the Minimum Release Age control is intended to prevent. The issue is fixed in Renovate 44.3.1; as a workaround, digest updates can be disabled or gated behind `dependencyDashboardApproval`.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| renovatebot | renovate | < 44.3.1 |
| renovatebot | renovate | < 15.4.0 |
| renovatebot | renovate | < 10.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Undergoing Analysis
Frequently Asked Questions
What is CVE-2026-88884?
How severe is CVE-2026-88884?
How do I fix CVE-2026-88884?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-88879Traefik is an HTTP reverse proxy and load balancer. In Traef…8.2
- CVE-2026-8888Version 3.0.7 of the Securly Chrome Extension downloads conf…7.5
- CVE-2026-88880Renovate before 44.11.3 fails to validate Link header destin…8.6
- CVE-2026-88881Renovate, a dependency update tool, follows pagination links…8.6
- CVE-2026-88882Renovate is a dependency update automation tool. In versions…8.6
- CVE-2026-88883Renovate is an automated dependency update tool. In versions…7.7
- CVE-2026-88885Renovate before 44.14.7 contains a command injection vulnera…7
- CVE-2026-88886Renovate is a dependency update automation tool. In versions…7.8
- CVE-2026-88887Renovate is a dependency update automation tool. When listin…8.6
- CVE-2026-88888Renovate before 44.14.7 contains a command injection vulnera…7
- CVE-2026-88889Renovate before 44.14.7 contains a command injection vulnera…7.8
- CVE-2026-8889Version 3.0.7 of the Securly Chrome Extension uses deprecate…7.5
Are you affected by CVE-2026-88884?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
