High severity7.5NVD Advisory· Published Jun 8, 2026· Updated Jun 12, 2026
CVE-2026-49234
CVE-2026-49234
Description
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes.
This only affects users who allow API access from untrusted networks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
routinatorcrates.io | < 0.15.2 | 0.15.2 |
Affected products
2cpe:2.3:a:nlnetlabs:routinator:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:nlnetlabs:routinator:*:*:*:*:*:*:*:*range: <0.15.2
- (no CPE)
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-gc6q-cwcj-3vh9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-49234ghsaADVISORY
- www.nlnetlabs.nl/downloads/routinator/CVE-2026-49234.txtnvdVendor AdvisoryWEB
- github.com/NLnetLabs/routinator/releases/tag/v0.15.2ghsaWEB
News mentions
0No linked articles in our index yet.