{"id":"CVE-2026-49235","aliases":["GHSA-5qf9-cf9c-hjc6"],"title":"Routinator crashes when encountering maliciously crafted RRDP XML files","summary":"Routinator crashes when encountering maliciously crafted RRDP XML files","severity":"high","cwe":["CWE-400","CWE-755","CWE-776"],"vendor":"routinator","product":"routinator","ecosystem":"rust","affected":["routinator <= 0.15.1"],"patched":["routinator 0.15.2"],"published":"2026-06-08","updated":"2026-06-12","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-5qf9-cf9c-hjc6","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49235"},{"url":"https://www.nlnetlabs.nl/downloads/routinator/CVE-2026-49235.txt"},{"url":"https://github.com/NLnetLabs/routinator/releases/tag/v0.15.2"},{"url":"https://github.com/advisories/GHSA-5qf9-cf9c-hjc6"}],"tags":["ghsa","rust"],"epss":0.00368,"epssPercentile":0.30478,"ingestedAt":"2026-07-07T15:41:59.874Z","slug":"CVE-2026-49235","body":"## Overview\n\nWhen Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.\n\n## Affected packages\n\n- `routinator <= 0.15.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `routinator 0.15.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}