Home
HIGH: 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:HDefault status
affected
0.15.2 (semver) before *
unaffected
Description
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks.
Problem types
CWE-20 Improper Input Validation
Product status
0.15.2 (semver) before *
Timeline
| 2026-03-28: | Issue reported |
| 2026-06-08: | Fixes released |
Credits
X41 D-Sec GmbH
References
www.nlnetlabs.nl/downloads/routinator/CVE-2026-49234.txt