CVE-2026-54716: Valhalla
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unbounded memory growth in the worker. The zero-area geometry, rather than the other request options, triggers processing in src/loki/polygon_search.cc until the process is terminated by the out-of-memory killer. A single unauthenticated request can therefore stop a public-facing worker. Other endpoints that accept exclude_polygons, including /route, were not verified as affected. No fixed version is available as of this review.
Affected products
- Valhalla Valhalla: up to and including 3.7.0
Published 2026-09-17. Last modified 2026-09-24.