Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.
References
| Link | Resource |
|---|---|
| https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49233.txt | Vendor Advisory |
Configurations
History
12 Jun 2026, 01:33
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49233.txt - Vendor Advisory | |
| First Time |
Nlnetlabs
Nlnetlabs routinator |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CPE | cpe:2.3:a:nlnetlabs:routinator:*:*:*:*:*:*:*:* |
08 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-08 15:16
Updated : 2026-06-12 01:33
NVD link : CVE-2026-49233
Mitre link : CVE-2026-49233
CVE.ORG link : CVE-2026-49233
JSON object : View
Products Affected
nlnetlabs
- routinator
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
