CVE-2026-49233

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:nlnetlabs:routinator:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-08 15:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-49233

Mitre link : CVE-2026-49233

CVE.ORG link : CVE-2026-49233


JSON object : View

Products Affected

nlnetlabs

  • routinator
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')