Junglewise Threat Intelligence

CVE-2026-49233: NLnet Labs Routinator path traversal in rsync URI module component

CVE-2026-49233 · Severity: high · CVSS 4 · Published 2026-06-08

Technologies: NLnet Labs Routinator, routinator (crates.io). Vendors: NLnet Labs, crates.io.

Executive brief

NLnet Labs Routinator is a software tool used by network operators to verify the security of internet routing. A vulnerability in how it handles data from external servers could allow an attacker to manipulate the local cache files used for routing validation. This could lead to data corruption or service disruptions, potentially affecting the reliability of the network's routing security.

Technical details

A path traversal vulnerability (CWE-22) exists in Routinator due to insufficient validation of the module component in rsync URIs. When Routinator processes these URIs to create local filesystem paths for its cache, it fails to filter out directory traversal sequences like '..'. A remote attacker providing a malicious rsync URI can escape the intended cache directory, potentially gaining unauthorized access to or modifying the entire Routinator rsync cache. This issue is resolved in version 0.15.2 by extending path component checks to include the authority and module parts of the URI.

Affected products

  • NLnet Labs Routinator <= 0.15.1

Timeline

  • 2026-06-08: disclosed
  • 2026-06-08: patched: Fixed in version 0.15.2
  • 2026-06-08: advisory

References

Related threats