CVE-2026-49233: Nlnetlabs Routinator
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.
Affected products
- Nlnetlabs Routinator: before 0.15.2 (fixed in 0.15.2)
Published 2026-06-08. Last modified 2026-07-23.