High severity7.5NVD Advisory· Published Jun 8, 2026· Updated Jun 12, 2026
CVE-2026-49233
CVE-2026-49233
Description
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
routinatorcrates.io | < 0.15.2 | 0.15.2 |
Affected products
3(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:nlnetlabs:routinator:*:*:*:*:*:*:*:*range: <0.15.2
- (no CPE)
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-33mj-99mg-8g73ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-49233ghsaADVISORY
- www.nlnetlabs.nl/downloads/routinator/CVE-2026-49233.txtnvdVendor AdvisoryWEB
- github.com/NLnetLabs/routinator/releases/tag/v0.15.2ghsaWEB
News mentions
1- Nlnetlabs Routinator: Three High-Severity Vulnerabilities Disclosed TogetherVypr Intelligence · Jun 8, 2026