Medium severity6.5NVD Advisory· Published May 13, 2021· Updated Jun 17, 2026
CVE-2021-29506
CVE-2021-29506
Description
GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vulnerability that may lead to Denial of Service. This has been patched in 2.4 and 3.0 See this pull request for the fix: https://github.com/graphhopper/graphhopper/pull/2304
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.graphhopper:graphhopper-navMaven | < 2.4 | 2.4 |
Affected products
3cpe:2.3:a:graphhopper:graphhopper:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:graphhopper:graphhopper:*:*:*:*:*:*:*:*range: >=2.0,<2.4
- (no CPE)range: >= 2.0, < 2.4
Patches
Vulnerability mechanics
References
5- github.com/graphhopper/graphhopper/commit/eb189be1fa7443ebf4ae881e737a18f818c95f41nvdPatchThird Party AdvisoryWEB
- github.com/graphhopper/graphhopper/pull/2304nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-hf44-3mx6-vhhwghsaADVISORY
- github.com/graphhopper/graphhopper/security/advisories/GHSA-hf44-3mx6-vhhwnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-29506ghsaADVISORY
News mentions
0No linked articles in our index yet.