Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. | |
| Title | Routinator cache path traversal using rogue rsync URIs | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NLnet Labs
Published:
Updated: 2026-06-08T15:38:59.530Z
Reserved: 2026-05-28T08:28:56.664Z
Link: CVE-2026-49233
No data.
Status : Received
Published: 2026-06-08T15:16:47.693
Modified: 2026-06-08T15:16:47.693
Link: CVE-2026-49233
No data.
OpenCVE Enrichment
No data.