PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49234 NLnet Labs CVE debrief

CVE-2026-49234 is a HIGH severity vulnerability in Routinator that causes a crash when a specifically crafted non-UTF-8 string is sent as a select-asn query parameter to the /api/v1/origins endpoint. This issue only affects users who allow API access from untrusted networks. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

Vendor
NLnet Labs
Product
Routinator
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-08
Original CVE updated
2026-06-12
Advisory published
2026-06-08
Advisory updated
2026-06-12

Who should care

Users of Routinator who allow API access from untrusted networks should be aware of this vulnerability and take steps to mitigate it.

Technical summary

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes.

Defensive priority

HIGH

Recommended defensive actions

  • Users should update to a version of Routinator that is not vulnerable.
  • Users should restrict API access to trusted networks only.

Evidence notes

The vulnerability has a CVSS score of 8.2 and is considered HIGH severity.

Official resources

CVE-2026-49234 was published on 2026-06-08T15:16:48.080Z and modified on 2026-06-12T01:28:23.370Z.