VendorsNLnet Labsroutinatorall versions
Vulnerabilities

NLnet Labs NLnetLabs Routinator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2023-39916
Possible path traversal when storing RRDP responses
Published 2023-09-13 · Modified
9.3EPSS 0.006
CVE-2026-49235
Routinator crashes on specifically crafted RRDP XML files
Published 2026-06-08 · Analyzed
8.7EPSS 0.005
CVE-2026-49233
Routinator cache path traversal using rogue rsync URIs
Published 2026-06-08 · Analyzed
8.3EPSS 0.005
CVE-2026-49234
Routinator crashes on specifically crafted ASN strings in the API
Published 2026-06-08 · Analyzed
8.2EPSS 0.003
CVE-2021-43173
Hanging RRDP request
Published 2021-11-09 · Modified
7.5EPSS 0.015
CVE-2021-43172
Infinite length chain of RRDP repositories
Published 2021-11-09 · Modified
7.5EPSS 0.013
CVE-2021-43174
gzip transfer encoding caused out-of-memory crash
Published 2021-11-09 · Modified
7.5EPSS 0.012
CVE-2024-1622
Routinator terminates when RTR connection is reset too quickly after opening
Published 2024-02-26 · Analyzed
7.5EPSS 0.010
CVE-2021-41531
Invalid RPKI data could disable Route Origin Validation on RTR clients.
Published 2021-09-21 · Modified
7.5EPSS 0.009
CVE-2022-3029
Fatal error on incorrect base64 data in RRDP
Published 2022-09-13 · Modified
7.5EPSS 0.009
CVE-2023-39915
Crashes on parsing certain invalid RPKI objects
Published 2023-09-13 · Modified
7.5EPSS 0.006
CVE-2020-17366
An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate Revocation List files from the RPKI relying party's view.
Published 2020-08-05 · Modified
7.4EPSS 0.007