Impact
A bug in Traccar’s group hierarchy handling allows an authenticated user who can manage groups and request reports to create a cycle in the parent chain of groups. The code that resolves group relationships does not detect such cycles, leading to an uncontrolled recursive lookup when generating a trips or stops report. This recursion never terminates, exhausting CPU resources, pinning Jetty worker threads, and eventually draining the web/API worker pool, which results in a denial of service. The weakness is a classic uncontrolled recursion flaw (CWE‑674).
Affected Systems
The vulnerability affects the Traccar GPS tracking system in all releases prior to version 6.14.0. Users running any earlier Traccar package should treat those versions as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score of less than 1 % suggests that exploitation is currently unlikely. The issue is not listed in CISA’s KEV catalog. Because the flaw requires authentication and group‑management permissions, the attack vector is authenticated remote. Successful exploitation would lead to availability loss by tying up system resources; confidentiality and integrity are not directly compromised.
OpenCVE Enrichment