This only affects users who allow API access from untrusted networks.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
This issue is fixed in 0.15.2 and all later versions.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gc6q-cwcj-3vh9 | Routinator crashes when sending a maliciously crafted select-asn query parameter |
Fri, 12 Jun 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:nlnetlabs:routinator:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 08 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nlnetlabs
Nlnetlabs routinator |
|
| Vendors & Products |
Nlnetlabs
Nlnetlabs routinator |
Mon, 08 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. | |
| Title | Routinator crashes on specifically crafted ASN strings in the API | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NLnet Labs
Published:
Updated: 2026-06-08T15:39:39.130Z
Reserved: 2026-05-28T08:28:56.664Z
Link: CVE-2026-49234
Updated: 2026-06-08T15:39:24.735Z
Status : Analyzed
Published: 2026-06-08T15:16:48.080
Modified: 2026-06-12T01:28:23.370
Link: CVE-2026-49234
No data.
OpenCVE Enrichment
Updated: 2026-06-12T02:30:11Z
Github GHSA