# CVE-2025-0638

## Summary

- **CVE ID:** CVE-2025-0638
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-1286
- **Published:** Jan 22, 2025
- **Last Modified:** Mar 13, 2026

## Description

The initial code parsing the manifest did not check the content of the file names yet later code assumed that it was checked and panicked when encountering illegal characters, resulting in a crash of Routinator.

## Affected Products

- NLnet Labs — Routinator (0.14.1)

## References

- [CNA](https://www.nlnetlabs.nl/downloads/routinator/CVE-2025-0638.txt)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.48%
- **EPSS Percentile:** 39.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._