Valhalla · Valhalla · CVE-2026-54716
**Name of the Vulnerable Software and Affected Versions**
Valhalla versions prior to 3.7.1
**Description**
A POST request to the '/sources to targets' endpoint containing an `exclude polygons` ring formed by three collinear points can cause unbounded memory growth in the worker. This occurs because zero-area geometry triggers continuous processing in the `polygon search.cc` function until the process is terminated by the out-of-memory killer. A single unauthenticated request can stop a public-facing worker.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict or avoid using the `exclude polygons` parameter in the '/sources to targets' endpoint.