PatchSiren cyber security CVE debrief
CVE-2026-49234 NLnet Labs CVE debrief
CVE-2026-49234 is a HIGH severity vulnerability in Routinator that causes a crash when a specifically crafted non-UTF-8 string is sent as a select-asn query parameter to the /api/v1/origins endpoint. This issue only affects users who allow API access from untrusted networks. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
- Vendor
- NLnet Labs
- Product
- Routinator
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-08
- Original CVE updated
- 2026-06-12
- Advisory published
- 2026-06-08
- Advisory updated
- 2026-06-12
Who should care
Users of Routinator who allow API access from untrusted networks should be aware of this vulnerability and take steps to mitigate it.
Technical summary
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes.
Defensive priority
HIGH
Recommended defensive actions
- Users should update to a version of Routinator that is not vulnerable.
- Users should restrict API access to trusted networks only.
Evidence notes
The vulnerability has a CVSS score of 8.2 and is considered HIGH severity.
Official resources
-
CVE-2026-49234 CVE record
CVE.org
-
CVE-2026-49234 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
CVE-2026-49234 was published on 2026-06-08T15:16:48.080Z and modified on 2026-06-12T01:28:23.370Z.