๐Ÿ” CVE Alert

CVE-2026-54716

HIGH 7.5

Valhalla: Degenerate exclude_polygons (collinear points, zero area) causes OOM in /sources_to_targets

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unbounded memory growth in the worker. The zero-area geometry, rather than the other request options, triggers processing in src/loki/polygon_search.cc until the process is terminated by the out-of-memory killer. A single unauthenticated request can therefore stop a public-facing worker. Other endpoints that accept exclude_polygons, including /route, were not verified as affected. No fixed version is available as of this review.

CWE CWE-770
Vendor valhalla
Product valhalla
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for valhalla valhalla

Be the first to know when new high vulnerabilities affecting valhalla valhalla are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

valhalla / valhalla
<= 3.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/valhalla/valhalla/security/advisories/GHSA-qpf6-xp29-pg6r