CVE-2026-54716
Valhalla: Degenerate exclude_polygons (collinear points, zero area) causes OOM in /sources_to_targets
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unbounded memory growth in the worker. The zero-area geometry, rather than the other request options, triggers processing in src/loki/polygon_search.cc until the process is terminated by the out-of-memory killer. A single unauthenticated request can therefore stop a public-facing worker. Other endpoints that accept exclude_polygons, including /route, were not verified as affected. No fixed version is available as of this review.
| CWE | CWE-770 |
| Vendor | valhalla |
| Product | valhalla |
| Published | Sep 17, 2026 |
Get instant alerts for valhalla valhalla
Be the first to know when new high vulnerabilities affecting valhalla valhalla are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H