CVE-2026-49232

Description

A flaw was found in Routinator. A remote attacker can exploit this vulnerability by opening a large number of connections to the HTTP or RTR (Resource Public Key Infrastructure (RPKI) to Router) server. This can cause Routinator to exit, leading to a Denial of Service (DoS) for affected services. This issue primarily impacts users who expose their HTTP or RTR server to untrusted networks.

Statement

Important: Routinator is susceptible to a denial of service when its HTTP or RTR server is exposed to untrusted networks. A remote attacker can exhaust available file descriptors by opening numerous connections, causing the service to exit and disrupting RPKI validation. This impact is significant for deployments relying on Routinator for critical routing infrastructure.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)

When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.

Frequently Asked Questions

Want to get errata notifications? Sign up here.