# CVE-2023-39915

## Summary

- **CVE ID:** CVE-2023-39915
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-232, CWE-240
- **Published:** Sep 13, 2023
- **Last Modified:** Mar 13, 2026

## Description

NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.

## Affected Products

- NLnet Labs — Routinator (*)
- NLnet Labs — Routinator (0.12.2)

## References

- [CNA](https://nlnetlabs.nl/downloads/routinator/CVE-2023-39915.txt)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.35%
- **EPSS Percentile:** 56.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._