CVE-2026-88883

Summary

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].httpsPrivateKey was redacted in the field itself, the same private key value was not redacted if it also appeared elsewhere — for example in another configuration option or in a log message under a key other than httpsPrivateKey — causing the full private key to be written to Renovate's logs in cleartext. This affects deployments that configure Mutual TLS through hostRules[].httpsPrivateKey without passing the value through the documented secrets configuration. Anyone able to read the resulting logs can recover the private key. The issue is fixed in Renovate 44.14.4, which redacts any value supplied as hostRules[].httpsPrivateKey wherever it appears in the logs; as a workaround, supply the key via the secrets configuration.

Affected Software

VendorProductVersion RangeStatus
renovatebotrenovate0 < 44.14.44affected
renovatebotrenovate44.14.44unaffected
renovatebotrenovate0 < 44.14.44affected
renovatebotrenovate44.14.44unaffected
renovatebotrenovate0 < 44.14.44affected
renovatebotrenovate44.14.44unaffected
renovatebotrenovate0 < 44.14.44affected
renovatebotrenovate44.14.44unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 15.4.0affected
renovatebotrenovate15.4.0unaffected
renovatebotrenovate0 < 10.4.0affected
renovatebotrenovate10.4.0unaffected
renovatebotrenovate0 < 10.4.0affected
renovatebotrenovate10.4.0unaffected

Weaknesses

  • CWE-532: Insertion of Sensitive Information into Log File

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References