The initial code parsing the manifest did not check the content of the file names yet later code assumed that it was checked and panicked when encountering illegal characters, resulting in a crash of Routinator.
CVE ID: CVE-2025-0638
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
Vendor: NLnet Labs
Product: Routinator
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.71% (scored less or equal to compared to others)
EPSS Date: 2025-02-20 (when was this score calculated)