irrd
Internet Routing Registry daemon (IRRd)
Activity
- Latest release
- 2mo ago
- Total releases
- 47
- Cadence
- ~32 days
- Last 12 months
- 7
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- Dec 20, 2018
| Version | Released | |
|---|---|---|
4.5.3
patch
| ||
4.4.7
patch
| ||
4.5.2
patch
| ||
4.4.6
patch
| ||
4.5.1
patch
| ||
4.4.5
patch
| ||
4.5.0
minor
1 CVE
CVE-2026-28681
PYSEC-2026-2186
GHSA-22m3-c7vp-49fj
Mar 06, 2026
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation link in the resulting email can then point to an attacker-controlled domain. Opening the link in the email is sufficient to pass the token to the attacker, who can then use it on the real IRRD instance to take over the account. A compromised account can then be used to modify RPSL objects maintained by the account's mntners and perform other account actions. If the user had two-factor authentication configured, which is required for users with override access, an attacker is not able to log in, even after successfully resetting the password. This issue has been patched in versions 4.4.5 and 4.5.1. Affected versions
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.5.0
Fixed in
4.4.5
4.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
4.4.4
patch
1 CVE
CVE-2026-28681
PYSEC-2026-2186
GHSA-22m3-c7vp-49fj
Mar 06, 2026
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation link in the resulting email can then point to an attacker-controlled domain. Opening the link in the email is sufficient to pass the token to the attacker, who can then use it on the real IRRD instance to take over the account. A compromised account can then be used to modify RPSL objects maintained by the account's mntners and perform other account actions. If the user had two-factor authentication configured, which is required for users with override access, an attacker is not able to log in, even after successfully resetting the password. This issue has been patched in versions 4.4.5 and 4.5.1. Affected versions
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.5.0
Fixed in
4.4.5
4.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
4.3.3
patch
| ||
4.4.3
patch
1 CVE
CVE-2026-28681
PYSEC-2026-2186
GHSA-22m3-c7vp-49fj
Mar 06, 2026
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation link in the resulting email can then point to an attacker-controlled domain. Opening the link in the email is sufficient to pass the token to the attacker, who can then use it on the real IRRD instance to take over the account. A compromised account can then be used to modify RPSL objects maintained by the account's mntners and perform other account actions. If the user had two-factor authentication configured, which is required for users with override access, an attacker is not able to log in, even after successfully resetting the password. This issue has been patched in versions 4.4.5 and 4.5.1. Affected versions
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.5.0
Fixed in
4.4.5
4.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
4.3.2
patch
| ||
4.4.2
patch
1 CVE
CVE-2026-28681
PYSEC-2026-2186
GHSA-22m3-c7vp-49fj
Mar 06, 2026
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation link in the resulting email can then point to an attacker-controlled domain. Opening the link in the email is sufficient to pass the token to the attacker, who can then use it on the real IRRD instance to take over the account. A compromised account can then be used to modify RPSL objects maintained by the account's mntners and perform other account actions. If the user had two-factor authentication configured, which is required for users with override access, an attacker is not able to log in, even after successfully resetting the password. This issue has been patched in versions 4.4.5 and 4.5.1. Affected versions
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.5.0
Fixed in
4.4.5
4.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
4.4.1
patch
1 CVE
CVE-2026-28681
PYSEC-2026-2186
GHSA-22m3-c7vp-49fj
Mar 06, 2026
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation link in the resulting email can then point to an attacker-controlled domain. Opening the link in the email is sufficient to pass the token to the attacker, who can then use it on the real IRRD instance to take over the account. A compromised account can then be used to modify RPSL objects maintained by the account's mntners and perform other account actions. If the user had two-factor authentication configured, which is required for users with override access, an attacker is not able to log in, even after successfully resetting the password. This issue has been patched in versions 4.4.5 and 4.5.1. Affected versions
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.5.0
Fixed in
4.4.5
4.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
4.4.0
minor
1 CVE
CVE-2026-28681
PYSEC-2026-2186
GHSA-22m3-c7vp-49fj
Mar 06, 2026
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation link in the resulting email can then point to an attacker-controlled domain. Opening the link in the email is sufficient to pass the token to the attacker, who can then use it on the real IRRD instance to take over the account. A compromised account can then be used to modify RPSL objects maintained by the account's mntners and perform other account actions. If the user had two-factor authentication configured, which is required for users with override access, an attacker is not able to log in, even after successfully resetting the password. This issue has been patched in versions 4.4.5 and 4.5.1. Affected versions
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.5.0
Fixed in
4.4.5
4.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
4.3.1
patch
| ||
4.2.9
patch
| ||
4.3.0.post1
pre
| ||
4.3.0
minor
| ||
4.2.8
patch
| ||
4.2.7
patch
| ||
4.2.6
patch
| ||
4.2.5
patch
| ||
4.2.4
patch
| ||
4.2.3
patch
| ||
4.2.2
patch
1 CVE
CVE-2022-24798
GHSA-cqxx-66wh-8pjw
PYSEC-2022-178
Apr 01, 2022
Improper Removal of Sensitive Information Before Storage or Transfer in irrd
High
Network
Low
Low
None
IRRd did not always filter password hashes in query responses relating to The issue occurred:
The two GraphQL cases are visible in logs, allowing users to determine whether any existing objects had their hashes exposed. This has been fixed in IRRd 4.2.3 and the main branch. Versions in the 4.1.x series never were affected. Users of the 4.2.x series are strongly recommended to upgrade. All users running a more recent version from the main branch should update to the latest version. Alternatively, but not recommended, apply the patch manually [for 4.2.x] Affected versions
4.2.0
4.2.1
4.2.2
Fixed in
4.2.3
References
Updated Sep 24, 2024 · Source: OSV.dev | ||
4.2.1
patch
1 CVE
CVE-2022-24798
GHSA-cqxx-66wh-8pjw
PYSEC-2022-178
Apr 01, 2022
Improper Removal of Sensitive Information Before Storage or Transfer in irrd
High
Network
Low
Low
None
IRRd did not always filter password hashes in query responses relating to The issue occurred:
The two GraphQL cases are visible in logs, allowing users to determine whether any existing objects had their hashes exposed. This has been fixed in IRRd 4.2.3 and the main branch. Versions in the 4.1.x series never were affected. Users of the 4.2.x series are strongly recommended to upgrade. All users running a more recent version from the main branch should update to the latest version. Alternatively, but not recommended, apply the patch manually [for 4.2.x] Affected versions
4.2.0
4.2.1
4.2.2
Fixed in
4.2.3
References
Updated Sep 24, 2024 · Source: OSV.dev | ||
4.1.8
patch
| ||
4.2.0
minor
1 CVE
CVE-2022-24798
GHSA-cqxx-66wh-8pjw
PYSEC-2022-178
Apr 01, 2022
Improper Removal of Sensitive Information Before Storage or Transfer in irrd
High
Network
Low
Low
None
IRRd did not always filter password hashes in query responses relating to The issue occurred:
The two GraphQL cases are visible in logs, allowing users to determine whether any existing objects had their hashes exposed. This has been fixed in IRRd 4.2.3 and the main branch. Versions in the 4.1.x series never were affected. Users of the 4.2.x series are strongly recommended to upgrade. All users running a more recent version from the main branch should update to the latest version. Alternatively, but not recommended, apply the patch manually [for 4.2.x] Affected versions
4.2.0
4.2.1
4.2.2
Fixed in
4.2.3
References
Updated Sep 24, 2024 · Source: OSV.dev | ||
4.1.7
patch
| ||
4.1.6
patch
| ||
4.1.5
patch
| ||
4.1.4
patch
| ||
4.1.3
patch
| ||
4.1.2
patch
| ||
4.1.1
patch
| ||
4.1.0
minor
| ||
4.0.8
patch
| ||
4.0.7
patch
| ||
4.0.6
patch
| ||
4.0.5.post1
pre
| ||
4.0.4.post1
pre
| ||
4.0.4
patch
| ||
4.0.3
patch
| ||
4.0.2
patch
| ||
4.0.1
patch
| ||
4.0.0
initial
| ||
4.0.0rc1
pre
|