routinator
Activity
- Latest release
- 3mo ago
- Total releases
- 75
- Cadence
- ~11 days
- Last 12 months
- 2
Details
- License
- BSD-3-Clause
- First release
- Nov 01, 2018
| Version | Released | |
|---|---|---|
0.15.2
unknown
|
0.15.2
unknown
Dependencies (30)
+ 22 more |
|
0.15.1
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.15.1
unknown
Dependencies (30)
+ 22 more |
|
0.15.0
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.15.0
unknown
Dependencies (30)
+ 22 more |
|
0.15.0-rc1
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.15.0-rc1
unknown
Dependencies (30)
+ 22 more |
|
0.14.2
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.14.2
unknown
Dependencies (29)
+ 21 more |
|
0.14.1
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.14.1
unknown
Dependencies (29)
+ 21 more |
|
0.14.0
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.14.0
unknown
Dependencies (29)
+ 21 more |
|
0.14.0-rc3
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.14.0-rc3
unknown
Dependencies (29)
+ 21 more |
|
0.14.0-rc2
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.14.0-rc2
unknown
Dependencies (29)
+ 21 more |
|
0.14.0-rc1
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.14.0-rc1
unknown
Dependencies (29)
+ 21 more |
|
0.13.2
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.13.2
unknown
Dependencies (28)
+ 20 more |
|
0.13.1
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.13.1
unknown
Dependencies (29)
+ 21 more |
|
0.13.1-rc1
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.13.1-rc1
unknown
Dependencies (29)
+ 21 more |
|
0.13.0
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.13.0
unknown
Dependencies (29)
+ 21 more |
|
0.13.0-rc2
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.13.0-rc2
unknown
Dependencies (30)
+ 22 more |
|
0.12.2
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.12.2
unknown
Dependencies (34)
+ 26 more |
|
0.13.0-rc1
unknown
3 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev |
0.13.0-rc1
unknown
Dependencies (29)
+ 21 more |
|
0.12.1
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev |
0.12.1
unknown
Dependencies (33)
+ 25 more |
|
0.12.1-rc2
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev |
0.12.1-rc2
unknown
Dependencies (33)
+ 25 more |
|
0.12.1-rc1
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev |
0.12.1-rc1
unknown
Dependencies (33)
+ 25 more |
|
0.12.0
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev |
0.12.0
unknown
Dependencies (33)
+ 25 more |
|
0.12.0-rc1
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev |
0.12.0-rc1
unknown
Dependencies (33)
+ 25 more |
|
0.11.3
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev |
0.11.3
unknown
Dependencies (34)
+ 26 more |
|
0.11.2
unknown
5 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.11.2
unknown
Dependencies (34)
+ 26 more |
|
0.11.1
unknown
5 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.11.1
unknown
Dependencies (34)
+ 26 more |
|
0.11.1-rc1
unknown
5 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.11.1-rc1
unknown
Dependencies (34)
+ 26 more |
|
0.11.0
unknown
5 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.11.0
unknown
Dependencies (34)
+ 26 more |
|
0.11.0-rc2
unknown
5 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.11.0-rc2
unknown
Dependencies (34)
+ 26 more |
|
0.11.0-rc1
unknown
5 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.11.0-rc1
unknown
Dependencies (34)
+ 26 more |
|
0.10.2
unknown
5 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.10.2
unknown
Dependencies (28)
+ 20 more |
|
0.10.1
unknown
7 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43174
GHSA-6mv9-qcx2-3hh3
Nov 11, 2021
Memory exhaustion in routinator
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.1
unknown
Dependencies (28)
+ 20 more |
|
0.10.1-rc3
unknown
7 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43174
GHSA-6mv9-qcx2-3hh3
Nov 11, 2021
Memory exhaustion in routinator
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.1-rc3
unknown
Dependencies (28)
+ 20 more |
|
0.10.1-rc2
unknown
7 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43174
GHSA-6mv9-qcx2-3hh3
Nov 11, 2021
Memory exhaustion in routinator
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.1-rc2
unknown
Dependencies (28)
+ 20 more |
|
0.10.1-rc1
unknown
7 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43174
GHSA-6mv9-qcx2-3hh3
Nov 11, 2021
Memory exhaustion in routinator
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.1-rc1
unknown
Dependencies (28)
+ 20 more |
|
0.10.0
unknown
7 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43174
GHSA-6mv9-qcx2-3hh3
Nov 11, 2021
Memory exhaustion in routinator
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.0
unknown
Dependencies (27)
+ 19 more |
|
0.10.0-rc3
unknown
7 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43174
GHSA-6mv9-qcx2-3hh3
Nov 11, 2021
Memory exhaustion in routinator
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.0-rc3
unknown
Dependencies (27)
+ 19 more |
|
0.10.0-rc2
unknown
7 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43174
GHSA-6mv9-qcx2-3hh3
Nov 11, 2021
Memory exhaustion in routinator
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.0-rc2
unknown
Dependencies (27)
+ 19 more |
|
0.10.0-rc1
unknown
7 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43174
GHSA-6mv9-qcx2-3hh3
Nov 11, 2021
Memory exhaustion in routinator
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.0-rc1
unknown
Dependencies (27)
+ 19 more |
|
0.9.0
unknown
7 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2023-39916
GHSA-5rxf-fqch-7vqp
Sep 13, 2023
NLnet Labs’ Routinator vulnerable to path traversal
9.3
/ 10
Critical
Network
Low
None
Required
Changed
None
High
High
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it. Fixed in
0.12.2
References Updated Oct 03, 2025 · Source: OSV.dev
CVE-2022-3029
GHSA-m4vx-ccrf-w399
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files which are not correctly base 64 encoded are treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data. Fixed in
0.11.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43174
GHSA-6mv9-qcx2-3hh3
Nov 11, 2021
Memory exhaustion in routinator
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.9.0
unknown
Dependencies (28)
+ 20 more |
|
0.9.0-rc3
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.9.0-rc3
unknown
Dependencies (28)
+ 20 more |
|
0.9.0-rc2
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.9.0-rc2
unknown
Dependencies (28)
+ 20 more |
|
0.9.0-rc1
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.9.0-rc1
unknown
Dependencies (28)
+ 20 more |
|
0.8.3
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.3
unknown
Dependencies (28)
+ 20 more |
|
0.8.3-rc1
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.3-rc1
unknown
Dependencies (28)
+ 20 more |
|
0.8.2
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.2
unknown
Dependencies (28)
+ 20 more |
|
0.8.2-rc1
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.2-rc1
unknown
Dependencies (28)
+ 20 more |
|
0.8.1
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.1
unknown
Dependencies (28)
+ 20 more |
|
0.8.1-rc1
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.1-rc1
unknown
Dependencies (28)
+ 20 more |
|
0.8.0
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.0
unknown
Dependencies (28)
+ 20 more |
|
0.8.0-rc2
unknown
4 CVEs
CVE-2026-49233
GHSA-33mj-99mg-8g73
Jun 08, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
Network
Low
None
None
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49235
GHSA-5qf9-cf9c-hjc6
Jun 08, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
Network
Low
None
None
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2026-49234
GHSA-gc6q-cwcj-3vh9
Jun 08, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
Local
Low
None
None
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. Fixed in
0.15.2
References Updated Jun 12, 2026 · Source: OSV.dev
CVE-2021-43172
GHSA-m3x9-623g-35c4
May 24, 2022
Routinator infinite loop vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all. Fixed in
0.10.2
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.0-rc2
unknown
Dependencies (28)
+ 20 more |