mend renovate-ce

10 known vulnerabilities in mend renovate-ce, 4 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-88889 CVSS 8.5 high Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary…
  • CVE-2026-88888 CVSS 7.3 high Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped…
  • CVE-2026-88887 CVSS 9.2 critical Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links…
  • CVE-2026-88886 CVSS 8.5 high Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and…
  • CVE-2026-88885 CVSS 7.3 high Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in…
  • CVE-2026-88884 CVSS 6.9 medium Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce…
  • CVE-2026-88883 CVSS 8.3 high Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the…
  • CVE-2026-88882 CVSS 9.2 critical Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and…
  • CVE-2026-88881 CVSS 9.2 critical Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with…
  • CVE-2026-88880 CVSS 9.2 critical Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to…