NLnet Labs Routinator Denial-of-Service Vulnerability via Connection Flooding

Vulnerability

A denial-of-service vulnerability has been identified in NLnet Labs Routinator versions prior to and including 0.15.1. The issue arises because Routinator exits upon encountering any error while handling incoming HTTP or RTR connections. This includes recoverable errors, such as depleting available file descriptors. An attacker can exploit this vulnerability by opening a large number of connections to the HTTP or RTR server, causing Routinator to crash. This issue only affects users who expose their HTTP or RTR server to untrusted networks.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing Routinator to exit unexpectedly and disrupt service.

Remediation

Users are advised to upgrade to Routinator version 0.15.2 or later.

Added: Jun 8, 2026, 3:30 PM
Updated: Jun 8, 2026, 3:30 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
7.8
remediation
7.7
relevance
9.3
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.