CVE-2025-0638: Nlnet Labs Routinator
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The initial code parsing the manifest did not check the content of the file names yet later code assumed that it was checked and panicked when encountering illegal characters, resulting in a crash of Routinator.
Affected products
- Nlnet Labs Routinator: before 0.14.1 (fixed in 0.14.1)
Published 2025-01-22. Last modified 2026-06-17.