CVE-2026-49233

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:nlnetlabs:routinator:*:*:*:*:*:*:*:*

History

12 Jun 2026, 01:33

Type Values Removed Values Added
References () https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49233.txt - () https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49233.txt - Vendor Advisory
First Time Nlnetlabs
Nlnetlabs routinator
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:nlnetlabs:routinator:*:*:*:*:*:*:*:*

08 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 15:16

Updated : 2026-06-12 01:33


NVD link : CVE-2026-49233

Mitre link : CVE-2026-49233

CVE.ORG link : CVE-2026-49233


JSON object : View

Products Affected

nlnetlabs

  • routinator
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')