PT-2026-95079 · Valhalla · Valhalla

·

CVE-2026-54716

·

Published

2026-09-17

·

Updated

2026-10-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Valhalla versions prior to 3.7.1
Description A POST request to the '/sources to targets' endpoint containing an exclude polygons ring formed by three collinear points can cause unbounded memory growth in the worker. This occurs because zero-area geometry triggers continuous processing in the polygon search.cc function until the process is terminated by the out-of-memory killer. A single unauthenticated request can stop a public-facing worker.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary mitigation, restrict or avoid using the exclude polygons parameter in the '/sources to targets' endpoint.

Exploit

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54716
GHSA-QPF6-XP29-PG6R

Affected Products

Valhalla