Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2188615
AlmaLinux
5895
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17166
BellSoft Hardened Containers
744
Bitnami
9227
Chainguard
1021546
CleanStart
3467
CRAN
14
crates.io
2727
Debian
67565
Echo
6669
GHC
3
GIT
106733
GitHub Actions
55
Go
9194
Hackage
32
Hex
354
Julia
1713
Linux
29368
Mageia
6211
Maven
7008
MinimOS
143153
npm
228633
NuGet
1862
opam
29
openEuler
8674
openSUSE
14360
OSS-Fuzz
4006
Packagist
7081
Pub
11
PyPI
25132
Red Hat
23216
Rocky Linux
4266
Root
19507
RubyGems
4717
SUSE
23067
SwiftURL
60
TuxCare
9385
Ubuntu
64552
VSCode
21
Wolfi
287408
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-8wc6-vgrq-x6cf
npm/renovate
Child processes spawned by Renovate incorrectly have full access to environment variables
13 Feb
Fix available
Severity - 5.5 (Medium)
CLEANSTART-2026-BQ28777
CleanStart/renovate
Security fix for ghsa-8wc6-vgrq-x6cf applied in: renovate 43.4.3-r1, renovate 43.4.4-r0
5 days ago
Fix available
CVE-2026-76227
github.com/renovatebot/renovate
Renovate 42.68.1 before 42.96.3 Environment Variable Exposure
19 Aug
Fix available
Severity - 6.8 (Medium)
Vulnerability Database - OSV