Executive brief
NLnet Labs Routinator is a software tool used by network operators to verify the security of internet routing. A vulnerability in how it handles data from external servers could allow an attacker to manipulate the local cache files used for routing validation. This could lead to data corruption or service disruptions, potentially affecting the reliability of the network's routing security.
Technical details
A path traversal vulnerability (CWE-22) exists in Routinator due to insufficient validation of the module component in rsync URIs. When Routinator processes these URIs to create local filesystem paths for its cache, it fails to filter out directory traversal sequences like '..'. A remote attacker providing a malicious rsync URI can escape the intended cache directory, potentially gaining unauthorized access to or modifying the entire Routinator rsync cache. This issue is resolved in version 0.15.2 by extending path component checks to include the authority and module parts of the URI.
Affected products
- NLnet Labs Routinator <= 0.15.1
Timeline
- 2026-06-08: disclosed
- 2026-06-08: patched: Fixed in version 0.15.2
- 2026-06-08: advisory