CVE-2026-49235: Nlnetlabs Routinator

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

Affected products

  • Nlnetlabs Routinator: before 0.15.2 (fixed in 0.15.2)

Published 2026-06-08. Last modified 2026-07-23.