CVE-2026-88883 PUBLISHED

Renovate before 44.14.4 TLS Private Key Log Sanitisation

Assigner: VulnCheck
Reserved: 10.09.2026 Published: 10.09.2026 Updated: 10.09.2026

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].httpsPrivateKey was redacted in the field itself, the same private key value was not redacted if it also appeared elsewhere — for example in another configuration option or in a log message under a key other than httpsPrivateKey — causing the full private key to be written to Renovate's logs in cleartext. This affects deployments that configure Mutual TLS through hostRules[].httpsPrivateKey without passing the value through the documented secrets configuration. Anyone able to read the resulting logs can recover the private key. The issue is fixed in Renovate 44.14.4, which redacts any value supplied as hostRules[].httpsPrivateKey wherever it appears in the logs; as a workaround, supply the key via the secrets configuration.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 8.3

Product Status

Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 44.14.44 (excl.)
  • Version 44.14.44 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 44.14.44 (excl.)
  • Version 44.14.44 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 44.14.44 (excl.)
  • Version 44.14.44 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 44.14.44 (excl.)
  • Version 44.14.44 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 15.4.0 (excl.)
  • Version 15.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 10.4.0 (excl.)
  • Version 10.4.0 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 0 to 10.4.0 (excl.)
  • Version 10.4.0 is unaffected

Credits

  • jamietanna reporter

References

Problem Types

  • Insertion of Sensitive Information into Log File CWE