VYPR
High severity7.5NVD Advisory· Published Sep 17, 2026

CVE-2026-54716

CVE-2026-54716

Description

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unbounded memory growth in the worker. The zero-area geometry, rather than the other request options, triggers processing in src/loki/polygon_search.cc until the process is terminated by the out-of-memory killer. A single unauthenticated request can therefore stop a public-facing worker. Other endpoints that accept exclude_polygons, including /route, were not verified as affected. No fixed version is available as of this review.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Valhalla/Valhallallm-fuzzy2 versions
    <=3.7.0+ 1 more
    • (no CPE)range: <=3.7.0
    • (no CPE)range: <=3.7.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.