Routinator cache path traversal using rogue rsync URIs
CVE-2026-49233

8.3HIGH

Key Information:

Vendor

Nlnet Labs

Vendor
CVE Published:
8 June 2026

What is CVE-2026-49233?

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

Affected Version(s)

Routinator 0.15.2

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

X41 D-Sec GmbH
.