Description
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unbounded memory growth in the worker. The zero-area geometry, rather than the other request options, triggers processing in src/loki/polygon_search.cc until the process is terminated by the out-of-memory killer. A single unauthenticated request can therefore stop a public-facing worker. Other endpoints that accept exclude_polygons, including /route, were not verified as affected. No fixed version is available as of this review.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Out‑of‑Memory
Action: Apply Mitigation
AI Analysis

Impact

Valhalla is an open source routing engine that exposes a /sources_to_targets endpoint. In versions 3.7.0 and earlier a POST request containing an exclude_polygons ring composed of three collinear points, which results in a zero‑area geometry, triggers unbounded memory consumption in the worker. The process eventually terminates under the operating system's out‑of‑memory killer, causing the public‑facing worker to become non‑responsive for the duration of the abortion. This flaw is a classic case of CWE‑770: Uncontrolled Memory Allocation.

Affected Systems

The vulnerability affects the Valhalla routing engine (valhalla:valhalla) running any 3.7.0 or earlier release. The specific endpoint impacted is /sources_to_targets; other endpoints that accept exclude_polygons, such as /route, have not been verified to be affected. No fixed release is available at the time of this assessment.

Risk and Exploitability

The CVSS score of 7.5 denotes a high severity. The EPSS score is reported as less than 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated, network‑based POST request to the /sources_to_targets endpoint. An adversary can construct a minimal polygon with collinear points to provoke unbounded memory growth, causing a denial of service for a public-facing component. No special privileges or authentication are required to exploit the flaw.

Generated by OpenCVE AI on September 18, 2026 at 23:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Validate exclude_polygons geometry to reject degenerate zero‑area rings before processing
  • Implement request filtering or input validation to block POSTs containing degenerate or excessively large polygons
  • Enforce hard memory limits on Valhalla worker processes using container or OS resource controls
  • Monitor worker memory usage and alert on abnormal growth to trigger a graceful restart
  • Upgrade Valhalla to a fixed version once it becomes available

Generated by OpenCVE AI on September 18, 2026 at 23:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Valhalla
Valhalla valhalla
Vendors & Products Valhalla
Valhalla valhalla

Thu, 17 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unbounded memory growth in the worker. The zero-area geometry, rather than the other request options, triggers processing in src/loki/polygon_search.cc until the process is terminated by the out-of-memory killer. A single unauthenticated request can therefore stop a public-facing worker. Other endpoints that accept exclude_polygons, including /route, were not verified as affected. No fixed version is available as of this review.
Title Valhalla: Degenerate exclude_polygons (collinear points, zero area) causes OOM in /sources_to_targets
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Valhalla Valhalla
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T14:44:00.609Z

Reserved: 2026-06-15T23:07:33.231Z

Link: CVE-2026-54716

cve-icon Vulnrichment

Updated: 2026-09-18T14:39:51.473Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T20:16:52.730

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:00:12Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling