CVE-2026-49234: Nlnetlabs Routinator

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks.

Affected products

  • Nlnetlabs Routinator: before 0.15.2 (fixed in 0.15.2)

Published 2026-06-08. Last modified 2026-07-23.