
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-49235 is a denial-of-service vulnerability in NLnet Labs Routinator, an RPKI (Resource Public Key Infrastructure) validator, caused by improper handling of maliciously crafted Document Type Definitions (DTDs) encountered via RRDP (RPKI Repository Delta Protocol). When Routinator processes an XML file containing a specifically crafted DTD over RRDP, it crashes, disrupting route origin validation services. All versions up to and including 0.15.1 are affected; version 0.15.2 contains the fix. The vulnerability carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, NLnet Labs).
The root cause is classified under CWE-755 (Improper Handling of Exceptional Conditions), CWE-400 (Uncontrolled Resource Consumption), and CWE-776 (Improper Restriction of Recursive Entity References in DTDs — 'XML Entity Expansion'), indicating that Routinator fails to properly restrict or handle recursive entity definitions within XML DTDs fetched via RRDP (GitHub Advisory). An attacker can serve a specially crafted XML file containing a malicious DTD through an RRDP repository endpoint; when Routinator fetches and parses this file during its normal RPKI validation cycle, the malformed DTD triggers an unhandled exceptional condition that causes the process to crash. No authentication or user interaction is required, and the attack complexity is low, making this straightforward to trigger remotely (GitHub Advisory).
Successful exploitation results in a crash of the Routinator process, causing a complete loss of availability for the RPKI route origin validation service. Since Routinator is used by network operators to validate BGP route origins, its disruption could degrade or disable route origin validation, potentially leaving networks more susceptible to BGP hijacking attacks during the outage window. There is no confidentiality or integrity impact on the vulnerable system itself, though downstream systems relying on Routinator's validation output may experience reduced availability (GitHub Advisory, NLnet Labs).
NLnet Labs has released Routinator version 0.15.2, which addresses this vulnerability; operators should upgrade immediately (GitHub Advisory, NLnet Labs Release). As a temporary workaround prior to patching, operators should restrict Routinator's RRDP connections to known-trusted repository sources at the network level and monitor Routinator logs for crash events. Implementing network-level filtering to block connections to untrusted or unexpected RRDP endpoints can reduce exposure (NLnet Labs).
NLnet Labs published a security advisory and released the patched version 0.15.2 on June 8, 2026, alongside a dedicated CVE advisory document (NLnet Labs). The vulnerability was detected by Qualys scanners and tracked by multiple vulnerability intelligence platforms including VulDB, OSV, and Tenable (Nessus plugin 321616). No significant broader community or social media discussion has been identified beyond standard vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."