Path Traversal Issue in Routinator by NLnet Labs
CVE-2026-49233
8.3HIGH
What is CVE-2026-49233?
A security flaw in Routinator allows attackers to manipulate the module component of rsync URIs, creating potential file system paths that lead to unauthorized access to the entire Routinator rsync cache. This vulnerability enables an attacker to exploit the caching system, leading to possible exposure of sensitive data stored within the cache directories.
Affected Version(s)
Routinator 0.15.2
