CVE-2026-49233

HIGH

Routinator cache path traversal using rogue rsync URIs

Title source: cna
STIX 2.1

Description

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0043
EPSS Percentile 34.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (3)
crates.io/routinator 0 - 0.15.2crates.io
NLnet Labs/Routinator 0.15.2
nlnetlabs/routinator < 0.15.2
Published Jun 08, 2026
Tracked Since Jun 08, 2026