Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49235

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

A flaw was found in Routinator. A remote attacker could exploit this vulnerability by providing a specially crafted Document Type Definition (DTD) file through the Relying Party RPKI Data Protocol (RRDP). This could lead to Routinator crashing, resulting in a Denial of Service (DoS) for the affected system.

Отчет

This is an Important denial of service flaw in Routinator, which could be triggered remotely by an unauthenticated attacker providing a specially crafted Document Type Definition (DTD) file via the Relying Party RPKI Data Protocol (RRDP). Successful exploitation would lead to the Routinator service crashing, impacting the availability of RPKI validation services.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=2486372rust-routinator: Routinator: Denial of Service via crafted Document Type Definition in RRDP

EPSS

Процентиль: 28%
0.00358
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

CVSS3: 7.5
debian
около 2 месяцев назад

When Routinator encounters a file via RRDP using a specifically crafte ...

github
около 2 месяцев назад

Routinator crashes when encountering maliciously crafted RRDP XML files

EPSS

Процентиль: 28%
0.00358
Низкий

7.5 High

CVSS3