Advisory Database
  • Advisories
  • Dependency Scanning
  1. cargo
  2. ›
  3. routinator
  4. ›
  5. CVE-2026-49235

CVE-2026-49235: Routinator crashes when encountering maliciously crafted RRDP XML files

June 8, 2026 (updated June 12, 2026)

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

References

  • github.com/NLnetLabs/routinator/releases/tag/v0.15.2
  • github.com/advisories/GHSA-5qf9-cf9c-hjc6
  • nvd.nist.gov/vuln/detail/CVE-2026-49235
  • www.nlnetlabs.nl/downloads/routinator/CVE-2026-49235.txt

Code Behaviors & Features

Detect and mitigate CVE-2026-49235 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.15.2

Fixed versions

  • 0.15.2

Solution

Upgrade to version 0.15.2 or above.

Impact 8.6 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption
  • CWE-755: Improper Handling of Exceptional Conditions
  • CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

Source file

cargo/routinator/CVE-2026-49235.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:04 +0000.