{"api_version":"v1","generated_at":"2026-10-09T07:55:00+00:00","product":{"cve_count":21,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-renovatebot-renovate-af95273b6816","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/renovate","name":"renovate","next_cursor":null,"observations":[{"affected":"renovate: < 44.14.7; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88889","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88889","fixed":"renovate: 44.14.7; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0","last_modified":"2026-09-29T22:10:43.498Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-f2v7-35mm-3hx7","primary_source":"","published":"2026-09-10T13:05:38.147Z"},{"affected":"renovate: < 44.14.7; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88888","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88888","fixed":"renovate: 44.14.7; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0","last_modified":"2026-09-29T22:10:42.810Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-v85g-rq5w-c46q","primary_source":"","published":"2026-09-10T13:05:37.458Z"},{"affected":"renovate: < 44.11.2; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88887","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88887","fixed":"renovate: 44.11.2; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0","last_modified":"2026-09-29T22:10:42.139Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-v73q-hvqx-hxwx","primary_source":"","published":"2026-09-10T13:05:36.769Z"},{"affected":"renovate: < 44.14.7; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88886","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88886","fixed":"renovate: 44.14.7; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0","last_modified":"2026-09-29T22:10:41.481Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-7chm-46wx-888m","primary_source":"","published":"2026-09-10T13:05:36.051Z"},{"affected":"renovate: < 44.14.7; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88885","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88885","fixed":"renovate: 44.14.7; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0","last_modified":"2026-09-29T22:10:40.812Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-mpf8-qxrw-gq3w","primary_source":"","published":"2026-09-10T13:05:35.356Z"},{"affected":"renovate: < 44.3.1; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88884","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88884","fixed":"renovate: 44.3.1; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0","last_modified":"2026-09-29T22:10:40.134Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-g4qr-hw2h-687r","primary_source":"","published":"2026-09-10T13:05:34.657Z"},{"affected":"renovate: < 44.14.4; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88883","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88883","fixed":"renovate: 44.14.4; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0","last_modified":"2026-09-29T22:10:39.458Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-4hmw-qw74-vrhm","primary_source":"","published":"2026-09-10T13:05:33.976Z"},{"affected":"renovate: < 44.11.2; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88882","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88882","fixed":"renovate: 44.11.2; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0","last_modified":"2026-09-29T22:10:38.475Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-rh7w-ccch-gh49","primary_source":"","published":"2026-09-10T13:05:33.310Z"},{"affected":"renovate: < 44.11.3; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88881","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88881","fixed":"renovate: 44.11.3; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0","last_modified":"2026-09-29T22:10:37.776Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-w57v-h33h-835c","primary_source":"","published":"2026-09-10T13:05:32.249Z"},{"affected":"renovate: < 44.11.3; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88880","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88880","fixed":"renovate: 44.11.3; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0","last_modified":"2026-09-29T22:10:37.093Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-9hmg-9h89-jhmx","primary_source":"","published":"2026-09-10T13:05:31.574Z"},{"affected":"39.53.0 < 40.33.0","affected_versions_present":true,"cve_id":"CVE-2026-76233","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76233","fixed":"40.33.0","last_modified":"2026-08-19T14:45:31.617Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-xjr7-3c3g-m763","primary_source":"","published":"2026-08-19T14:02:13.767Z"},{"affected":"31.51.0 < 40.33.0","affected_versions_present":true,"cve_id":"CVE-2026-76232","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76232","fixed":"40.33.0","last_modified":"2026-08-25T01:59:41.665Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-3f44-xw83-3pmg","primary_source":"","published":"2026-08-19T14:02:13.066Z"},{"affected":"32.135.0 < 40.33.0","affected_versions_present":true,"cve_id":"CVE-2026-76231","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76231","fixed":"40.33.0","last_modified":"2026-08-20T16:06:47.842Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-36j9-mx87-2cff","primary_source":"","published":"2026-08-19T14:02:12.328Z"},{"affected":"35.63.0 < 40.33.0","affected_versions_present":true,"cve_id":"CVE-2026-76230","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76230","fixed":"40.33.0","last_modified":"2026-08-21T19:28:44.635Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-fr4j-65pv-gjjj","primary_source":"","published":"2026-08-19T14:02:11.620Z"},{"affected":"39.218.0 < 40.33.0","affected_versions_present":true,"cve_id":"CVE-2026-76229","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76229","fixed":"40.33.0","last_modified":"2026-08-20T15:22:57.662Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-xv56-3wq5-9997","primary_source":"","published":"2026-08-19T14:02:10.888Z"},{"affected":"renovate: 32.124.0 < 42.68.5; renovate-ce: < 13.3.0; renovate-ee-server: < 13.3.0; renovate-ee-worker: < 13.3.0","affected_versions_present":true,"cve_id":"CVE-2026-76228","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76228","fixed":"renovate: 42.68.5; renovate-ce: 13.3.0; renovate-ee-server: 13.3.0; renovate-ee-worker: 13.3.0","last_modified":"2026-10-08T15:25:04.592Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-pfq2-hh62-7m96","primary_source":"","published":"2026-08-19T14:02:10.197Z"},{"affected":"renovate: 42.68.1 < 42.96.3, 43.0.0 < 43.4.4; renovate-ce: 13.3.0 < 13.6.0; renovate-ee-server: 13.3.0 < 13.6.0; renovate-ee-worker: 13.3.0 < 13.6.0","affected_versions_present":true,"cve_id":"CVE-2026-76227","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76227","fixed":"renovate: 42.96.3, 43.4.4; renovate-ce: 13.6.0; renovate-ee-server: 13.6.0; renovate-ee-worker: 13.6.0","last_modified":"2026-10-08T15:25:04.010Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-8wc6-vgrq-x6cf","primary_source":"","published":"2026-08-19T14:02:09.384Z"},{"affected":"renovate: 43.65.0 < 43.102.11","affected_versions_present":true,"cve_id":"CVE-2026-76226","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76226","fixed":"renovate: 43.102.11","last_modified":"2026-10-08T15:25:03.450Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-5vjq-5jmg-39xq","primary_source":"","published":"2026-08-19T14:02:08.689Z"},{"affected":"renovate: 37.158.0 < 37.199.0","affected_versions_present":true,"cve_id":"CVE-2024-58376","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-58376","fixed":"renovate: 37.199.0","last_modified":"2026-09-29T22:10:34.429Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-rqgv-292v-5qgr","primary_source":"","published":"2026-08-19T14:01:49.687Z"},{"affected":"19.180.0 < 23.25.1","affected_versions_present":true,"cve_id":"CVE-2020-37267","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-37267","fixed":"23.25.1","last_modified":"2026-08-19T15:31:29.314Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-36rh-ggpr-j3gj","primary_source":"","published":"2026-08-19T14:01:49.017Z"},{"affected":"13.87.0 < 19.38.7","affected_versions_present":true,"cve_id":"CVE-2019-25766","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-25766","fixed":"19.38.7","last_modified":"2026-08-25T01:52:11.825Z","patch_url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-v7x3-7hw7-pcjg","primary_source":"","published":"2026-08-19T14:01:48.308Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"renovatebot"}}
