CVE-2020-17366
NixOS vulnerability analysis and mitigation

Overview

An issue was discovered in NLnet Labs Routinator versions 0.1.0 through 0.7.1, identified as CVE-2020-17366. The vulnerability allows remote attackers to bypass intended access restrictions or cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation '.roa' files or X509 Certificate Revocation List files from the RPKI relying party's view. This vulnerability was discovered and disclosed in August 2020 (NVD).

Technical details

The vulnerability has a CVSS v3.1 base score of 7.4 (HIGH) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H. The issue stems from improper validation of missing files referenced in manifests, which could lead to incomplete or compromised validation of RPKI data. When a manifest references non-existing files or there are checksum mismatches between the manifest and ROA files, the system should consider the whole manifest invalid (GitHub Issue).

Impact

The exploitation of this vulnerability can result in severe operational issues in real networks. In a specific attack scenario, if certain ROA files are withheld, it could cause BGP announcements to be incorrectly marked as invalid, potentially leading to network downtime. For example, if an attacker strategically removes specific ROA files while leaving others, it could result in incomplete VRP (Validated ROA Payload) sets that incorrectly invalidate legitimate BGP announcements (GitHub Issue).

Exploitability

The vulnerability can be exploited by an attacker in a man-in-the-middle (MITM) position who can intercept and manipulate the rsync channel. The attacker could strategically withhold certain .roa files from the validator's view or corrupt files with garbage data, leading to incomplete or incorrect validation results (GitHub Issue).

Mitigation and workarounds

The vulnerability was fixed in Routinator version 0.8.0. The update includes significant changes to validation rules following draft-ietf-sidrops-6486bis, where any invalid object mentioned on the manifest will lead to the issuing CA and all its objects being rejected. The fix also includes stricter CRL handling, requiring each CA to have exactly one CRL that matches the manifest's EE certificate (Release Notes).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • headlamp-fips
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • argo-workflows-3.7
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-32773MEDIUM6.1
  • NixOS logoNixOS
  • spark
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management