---
cve: "CVE-2026-49233"
severity: "HIGH"
cvss: 8.3
epss: "45%"
vendor: "NLnet Labs"
kev: false
exploited: false
published: "2026-06-08 15:16:47"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T16:24:39+02:00"
---

# CVE-2026-49233

> 8.3 HIGH

## Beschreibung

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 0cf9104efa730ebc2de6bbd880e9bcee50de10d9 (Commit)

## Referenzen

- <https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49233.txt>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-49233) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
