Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.
References
| Link | Resource |
|---|---|
| https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49233.txt | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-06-08 15:16
Updated : 2026-07-23 07:10
NVD link : CVE-2026-49233
Mitre link : CVE-2026-49233
CVE.ORG link : CVE-2026-49233
JSON object : View
Products Affected
nlnetlabs
- routinator
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
