internet_routing_registry_daemon_project CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

internet_routing_registry_daemon_project vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to internet_routing_registry_daemon_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-28681 Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation link in the resulting email can then point to an attacker-controlled domain. Opening the link in the email is sufficient to pass the token to the attacker, who can then use it on the [email protected] 8.1 0.03% 2026-03-06 2026-04-21
CVE-2022-24798 Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. IRRd did not always filter password hashes in query responses relating to `mntner` objects and database exports. This may have allowed adversaries to retrieve some of these hashes, perform a brute-force search for the clear-text passphrase, and use these to make unauthorised changes to affected IRR objects. This issue only affected instances that process password hashes, which means i [email protected] 7.5 0.37% 2022-03-31 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence