CVE-2026-88884
mediumCVSS v3 Base Score
5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
Low
Availability
None
Published: September 10, 2026 (0 days ago)
Last Modified: September 10, 2026
Vendor: Red Hat
Source: REDHAT
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in Renovate, a dependency update automation tool. This vulnerability allows for the bypass of the `minimumReleaseAge` security control when processing digest updates. A remote attacker could exploit this by publishing a malicious dependency version, which Renovate would then prematurely propose in a pull request, potentially leading to the execution of untrusted code in continuous integration (CI) workflows before stability checks are complete. This undermines the intended protection against unstable or malicious dependency introductions.