{"id":"CVE-2021-29506","details":"GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vulnerability that may lead to Denial of Service. This has been patched in 2.4 and 3.0 See this pull request for the fix: https://github.com/graphhopper/graphhopper/pull/2304","aliases":["GHSA-hf44-3mx6-vhhw"],"modified":"2026-07-09T10:01:12.986500Z","published":"2021-05-13T19:15:07.983Z","references":[{"type":"ADVISORY","url":"https://github.com/graphhopper/graphhopper/security/advisories/GHSA-hf44-3mx6-vhhw"},{"type":"FIX","url":"https://github.com/graphhopper/graphhopper/commit/eb189be1fa7443ebf4ae881e737a18f818c95f41"},{"type":"FIX","url":"https://github.com/graphhopper/graphhopper/pull/2304"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/graphhopper/graphhopper","events":[{"introduced":"7e3a98bd316745a7cc48ba78958624b9544e4d61"},{"fixed":"3bef7ead91d01adfd4fbea459bcc62de1f0279fc"},{"fixed":"eb189be1fa7443ebf4ae881e737a18f818c95f41"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:graphhopper:graphhopper:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0"},{"fixed":"2.4"}]}}],"versions":["2.3","3.0-pre4","3.0-pre3","3.0-pre2","3.0-pre1","2.2","2.1","2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29506.json","vanir_signatures_modified":"2026-07-09T10:01:12Z","vanir_signatures":[{"source":"https://github.com/graphhopper/graphhopper/commit/3bef7ead91d01adfd4fbea459bcc62de1f0279fc","target":{"file":"navigation/src/main/java/com/graphhopper/navigation/NavigateResource.java","function":"getPointsFromRequest"},"deprecated":false,"digest":{"function_hash":"36142885775801880923327535353616592987","length":411},"id":"CVE-2021-29506-5a8dceed","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"36142885775801880923327535353616592987","length":411},"id":"CVE-2021-29506-7ef0e41e","signature_type":"Function","signature_version":"v1","source":"https://github.com/graphhopper/graphhopper/commit/eb189be1fa7443ebf4ae881e737a18f818c95f41","target":{"file":"navigation/src/main/java/com/graphhopper/navigation/NavigateResource.java","function":"getPointsFromRequest"}},{"source":"https://github.com/graphhopper/graphhopper/commit/3bef7ead91d01adfd4fbea459bcc62de1f0279fc","target":{"file":"navigation/src/main/java/com/graphhopper/navigation/NavigateResource.java"},"deprecated":false,"digest":{"line_hashes":["189626477168851777122880960144033487883","137275567613185398488357888955700532385","327134461445047257875801787977154168807","323202411778049434703774547551118540250","212398785548982498557687372389225794540","185973443862456284605407239049739654715","259759268823146020648102035072435108275"],"threshold":0.9},"id":"CVE-2021-29506-b2a0b268","signature_type":"Line","signature_version":"v1"},{"digest":{"line_hashes":["189626477168851777122880960144033487883","137275567613185398488357888955700532385","327134461445047257875801787977154168807","323202411778049434703774547551118540250","212398785548982498557687372389225794540","185973443862456284605407239049739654715","259759268823146020648102035072435108275"],"threshold":0.9},"id":"CVE-2021-29506-c7eec5f0","signature_type":"Line","signature_version":"v1","source":"https://github.com/graphhopper/graphhopper/commit/eb189be1fa7443ebf4ae881e737a18f818c95f41","target":{"file":"navigation/src/main/java/com/graphhopper/navigation/NavigateResource.java"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}