CVE-2026-49235

Description

A flaw was found in Routinator. A remote attacker could exploit this vulnerability by providing a specially crafted Document Type Definition (DTD) file through the Relying Party RPKI Data Protocol (RRDP). This could lead to Routinator crashing, resulting in a Denial of Service (DoS) for the affected system.

Statement

This is an Important denial of service flaw in Routinator, which could be triggered remotely by an unauthenticated attacker providing a specially crafted Document Type Definition (DTD) file via the Relying Party RPKI Data Protocol (RRDP). Successful exploitation would lead to the Routinator service crashing, impacting the availability of RPKI validation services.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (Other)

If parsed, recursive entity references allow the attacker to expand data exponentially, quickly consuming all system resources.

Frequently Asked Questions

Want to get errata notifications? Sign up here.