Denial of Service Vulnerability in Routinator by NLnet Labs
CVE-2026-49232

8.7HIGH

Key Information:

Vendor

Nlnet Labs

Vendor
CVE Published:
8 June 2026

What is CVE-2026-49232?

An issue exists in Routinator where the service may terminate unexpectedly when encountering errors during incoming HTTP or RTR connections. This includes situations that could be recoverable, such as exhausting file descriptors. An attacker can exploit this vulnerability by inundating the server with a multitude of connection attempts, leading to service unavailability. This risk is particularly pertinent to users who expose their HTTP or RTR servers to untrusted networks, emphasizing the need for proper security configurations.

Affected Version(s)

Routinator 0.15.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

X41 D-Sec GmbH
.