Advisory Database
  • Advisories
  • Dependency Scanning
  1. cargo
  2. ›
  3. routinator
  4. ›
  5. CVE-2026-49233

CVE-2026-49233: Routinator has cache path traversal when processing the module component of rsync URIs

June 8, 2026 (updated June 12, 2026)

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

References

  • github.com/NLnetLabs/routinator/releases/tag/v0.15.2
  • github.com/advisories/GHSA-33mj-99mg-8g73
  • nvd.nist.gov/vuln/detail/CVE-2026-49233
  • www.nlnetlabs.nl/downloads/routinator/CVE-2026-49233.txt

Code Behaviors & Features

Detect and mitigate CVE-2026-49233 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.15.2

Fixed versions

  • 0.15.2

Solution

Upgrade to version 0.15.2 or above.

Impact 9.1 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Source file

cargo/routinator/CVE-2026-49233.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:22:36 +0000.