CVE-2026-28681Disclosure(internet_routing_registry_daemon_project / internet_routing_registry_daemon)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation link in the resulting email can then point to an attacker-controlled domain. Opening the link in the email is sufficient to pass the token to the attacker, who can then use it on the real IRRD instance to take over the account. A compromised account can then be used to modify RPSL objects maintained by the account's mntners and perform other account actions. If the user had two-factor authentication configured, which is required for users with override access, an attacker is not able to log in, even after successfully resetting the password. This issue has been patched in versions 4.4.5 and 4.5.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • internet_routing_registry_daemon

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-06); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
internet_routing_registry_daemon

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-06: 3Mentions · 2026-03-11: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-11: 103-0603-11
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-063
Disclosure2General1
2026-03-111
Disclosure1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28681 (CVSS:8.1, HIGH) is Awaiting Analysis. Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From ve..https://nvd.nist.gov/vuln/detail/CVE-2026-28681 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2026‑28681, noting its high CVSS score and impact on the Internet Routing Registry daemon, and links to the official NVD entry.

    0000030
    172 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28681 Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from v… https://www.cve.org/CVERecord?id=CVE-2026-28681 ----- Traducción: CVE-2026-28681 Int… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-28681, giving brief technical details about affected IRR daemon versions and linking to the official CVE record, without providing any exploit or patch information.

    0000029
    56 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28681 Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from v… https://www.cve.org/CVERecord?id=CVE-2026-28681

    Post summary

    The text briefly mentions CVE-2026-28681, noting affected IRR daemon versions, but provides no further technical, exploitation, or remediation details.

    00000217
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28681 - High Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before ve... https://www.thehackerwire.com/vulnerability/CVE-2026-28681/ https://t.co/KtirJ7Ox7D

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑28681) affecting certain Internet Routing Registry daemon version 4 releases has been disclosed; an external article is linked for more detail.

    0000037
    125 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appinternet_routing_registry_daemon_projectinternet_routing_registry_daemon---

Explore more