Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY21 SECURITY RECORDS

renovatebot

renovate

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record Renovate CLI. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-88889 10 Sep 2026 renovate: < 44.14.7; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0 renovate: 44.14.7; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0 Update reference ↗
CVE-2026-88888 10 Sep 2026 renovate: < 44.14.7; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0 renovate: 44.14.7; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0 Update reference ↗
CVE-2026-88887 10 Sep 2026 renovate: < 44.11.2; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0 renovate: 44.11.2; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0 Update reference ↗
CVE-2026-88886 10 Sep 2026 renovate: < 44.14.7; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0 renovate: 44.14.7; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0 Update reference ↗
CVE-2026-88885 10 Sep 2026 renovate: < 44.14.7; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0 renovate: 44.14.7; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0 Update reference ↗
CVE-2026-88884 10 Sep 2026 renovate: < 44.3.1; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0 renovate: 44.3.1; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0 Update reference ↗
CVE-2026-88883 10 Sep 2026 renovate: < 44.14.4; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0 renovate: 44.14.4; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0 Update reference ↗
CVE-2026-88882 10 Sep 2026 renovate: < 44.11.2; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0 renovate: 44.11.2; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0 Update reference ↗
CVE-2026-88881 10 Sep 2026 renovate: < 44.11.3; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0 renovate: 44.11.3; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0 Update reference ↗
CVE-2026-88880 10 Sep 2026 renovate: < 44.11.3; renovate-ce: < 15.4.0; renovate-ee-server: < 15.4.0; renovate-ee-worker: < 15.4.0; mend-renovate-ce: < 15.4.0; mend-renovate-enterprise-edition: < 10.4.0 renovate: 44.11.3; renovate-ce: 15.4.0; renovate-ee-server: 15.4.0; renovate-ee-worker: 15.4.0; mend-renovate-ce: 15.4.0; mend-renovate-enterprise-edition: 10.4.0 Update reference ↗
CVE-2026-76233 19 Aug 2026 39.53.0 < 40.33.0 40.33.0 Update reference ↗
CVE-2026-76232 19 Aug 2026 31.51.0 < 40.33.0 40.33.0 Update reference ↗
CVE-2026-76231 19 Aug 2026 32.135.0 < 40.33.0 40.33.0 Update reference ↗
CVE-2026-76230 19 Aug 2026 35.63.0 < 40.33.0 40.33.0 Update reference ↗
CVE-2026-76229 19 Aug 2026 39.218.0 < 40.33.0 40.33.0 Update reference ↗
CVE-2026-76228 19 Aug 2026 renovate: 32.124.0 < 42.68.5; renovate-ce: < 13.3.0; renovate-ee-server: < 13.3.0; renovate-ee-worker: < 13.3.0 renovate: 42.68.5; renovate-ce: 13.3.0; renovate-ee-server: 13.3.0; renovate-ee-worker: 13.3.0 Update reference ↗
CVE-2026-76227 19 Aug 2026 renovate: 42.68.1 < 42.96.3, 43.0.0 < 43.4.4; renovate-ce: 13.3.0 < 13.6.0; renovate-ee-server: 13.3.0 < 13.6.0; renovate-ee-worker: 13.3.0 < 13.6.0 renovate: 42.96.3, 43.4.4; renovate-ce: 13.6.0; renovate-ee-server: 13.6.0; renovate-ee-worker: 13.6.0 Update reference ↗
CVE-2026-76226 19 Aug 2026 renovate: 43.65.0 < 43.102.11 renovate: 43.102.11 Update reference ↗
CVE-2024-58376 19 Aug 2026 renovate: 37.158.0 < 37.199.0 renovate: 37.199.0 Update reference ↗
CVE-2020-37267 19 Aug 2026 19.180.0 < 23.25.1 23.25.1 Update reference ↗
CVE-2019-25766 19 Aug 2026 13.87.0 < 19.38.7 19.38.7 Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.