This only affects users that make their HTTP or RTR server available to untrusted networks.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
This issue is fixed in 0.15.2 and all later versions.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nlnetlabs
Nlnetlabs routinator |
|
| Vendors & Products |
Nlnetlabs
Nlnetlabs routinator |
Mon, 08 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such as running out of file descriptors. This condition can be triggered maliciously by an attacker by opening a large number of connections to the HTTP or RTR server. This only affects users that make their HTTP or RTR server available to untrusted networks. | |
| Title | Routinator exits when accepting an incoming HTTP or RTR connection fails | |
| Weaknesses | CWE-755 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NLnet Labs
Published:
Updated: 2026-06-08T15:38:10.504Z
Reserved: 2026-05-28T08:28:56.664Z
Link: CVE-2026-49232
Updated: 2026-06-08T15:38:07.264Z
Status : Awaiting Analysis
Published: 2026-06-08T15:16:47.293
Modified: 2026-06-09T15:20:23.743
Link: CVE-2026-49232
No data.
OpenCVE Enrichment
Updated: 2026-06-08T16:00:14Z