CVE-2026-49235 PUBLISHED

Routinator crashes on specifically crafted RRDP XML files

Assigner: NLnet Labs
Reserved: 28.05.2026 Published: 08.06.2026 Updated: 08.06.2026

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
CVSS Score: 8.7

Product Status

Vendor NLnet Labs
Product Routinator
Versions Default: affected
  • unaffected from 0.15.2 to * (excl.)

Solutions

This issue is fixed in 0.15.2 and all later versions.

Credits

  • X41 D-Sec GmbH finder

References

Problem Types

  • CWE-755 Improper Handling of Exceptional Conditions CWE