Impact
Valhalla is an open source routing engine that exposes a /sources_to_targets endpoint. In versions 3.7.0 and earlier a POST request containing an exclude_polygons ring composed of three collinear points, which results in a zero‑area geometry, triggers unbounded memory consumption in the worker. The process eventually terminates under the operating system's out‑of‑memory killer, causing the public‑facing worker to become non‑responsive for the duration of the abortion. This flaw is a classic case of CWE‑770: Uncontrolled Memory Allocation.
Affected Systems
The vulnerability affects the Valhalla routing engine (valhalla:valhalla) running any 3.7.0 or earlier release. The specific endpoint impacted is /sources_to_targets; other endpoints that accept exclude_polygons, such as /route, have not been verified to be affected. No fixed release is available at the time of this assessment.
Risk and Exploitability
The CVSS score of 7.5 denotes a high severity. The EPSS score is reported as less than 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated, network‑based POST request to the /sources_to_targets endpoint. An adversary can construct a minimal polygon with collinear points to provoke unbounded memory growth, causing a denial of service for a public-facing component. No special privileges or authentication are required to exploit the flaw.
OpenCVE Enrichment