{"id":"CVE-2026-52852","summary":"Traccar: Uncontrolled Infinite Loop DoS via Group Parent Cycle","details":"Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in that hierarchy. org.traccar.api.resource.GroupResource permits the parent cycle, while org.traccar.helper.model.AttributeUtil.lookup follows group parents without cycle detection, a visited set, or a depth limit. The storage-backed lookup reached through TripsConfig. and ReportUtils.slowTripsAndStops never terminates, pins a Jetty worker at high CPU after the client disconnects, and can exhaust the web/API worker pool when requests are repeated. The position-ingestion cache-backed path is not part of the confirmed affected scope. This issue is fixed in 6.14.0.","aliases":["GHSA-6qh3-234v-r254"],"modified":"2026-09-19T08:08:49.350773Z","published":"2026-09-17T18:32:07.436Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52852.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-674"]},"references":[{"type":"WEB","url":"https://github.com/traccar/traccar/releases/tag/v6.14.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52852.json"},{"type":"ADVISORY","url":"https://github.com/traccar/traccar/security/advisories/GHSA-6qh3-234v-r254"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52852"},{"type":"FIX","url":"https://github.com/traccar/traccar/commit/8f6f59ac29d8b1222254e938672a0d99098fd800"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/traccar/traccar","events":[{"introduced":"0"},{"fixed":"8f6f59ac29d8b1222254e938672a0d99098fd800"},{"fixed":"ff30348a1b664a1cb7c83045b87d8822fd2c43ef"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.14.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v6.13.3","v6.13.2","v6.13.1","v6.13.0","v6.12.2","v6.12.1","v6.12.0","v6.11.1","v6.11.0","v6.10.0","v6.9.1","v6.9.0","v6.8.1","v6.8.0","v6.7.3","v6.7.2","v6.7.1","v6.7.0","v6.6","v6.5","v6.4","v6.3","v6.2","v6.1","v6.0","v5.12","v5.11","v5.10","v5.9","v5.8","v5.7","v5.6","v5.5","v5.4","v5.3","v5.2","v5.1","v5.0","v4.15","v4.14","v4.13","v4.12","v4.11","v4.10","v4.9","v4.8","v4.7","v4.6","v4.5","v4.4","v4.3","v4.2","v4.1","v4.0","v3.17","v3.16","v3.15","v3.14","v3.13","v3.12","v3.11","v3.10","v3.9","v3.8","v3.7","v3.6","v3.5","v3.4","v3.2","v3.1","v3.0","v2.12","v2.11","v2.10","v2.9","v2.8","v2.7","v2.6","v2.5","v2.4","v2.3","v2.2","v2.1","v2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52852.json","vanir_signatures_modified":"2026-09-19T08:08:49Z","vanir_signatures":[{"id":"CVE-2026-52852-4442cbd4","signature_type":"Line","signature_version":"v1","source":"https://github.com/traccar/traccar/commit/8f6f59ac29d8b1222254e938672a0d99098fd800","target":{"file":"src/main/java/org/traccar/storage/Storage.java"},"deprecated":false,"digest":{"line_hashes":["145981258954537205342402960600975907674","218237586491466178441196031807176380699","283922167656577584951683626493895744097"],"threshold":0.9}},{"source":"https://github.com/traccar/traccar/commit/8f6f59ac29d8b1222254e938672a0d99098fd800","target":{"file":"src/main/java/org/traccar/api/BaseObjectResource.java","function":"update"},"deprecated":false,"digest":{"function_hash":"14781341254286207912317928950419529115","length":1343},"id":"CVE-2026-52852-5f078cc1","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/traccar/traccar/commit/8f6f59ac29d8b1222254e938672a0d99098fd800","target":{"file":"src/main/java/org/traccar/helper/model/AttributeUtil.java","function":"lookup"},"deprecated":false,"digest":{"function_hash":"251736128108783587273494174843256185974","length":1490},"id":"CVE-2026-52852-60045dc7","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["52192504670192532125905162757107455768","128721828672493007743544868844614286860","48088958998034016010521506020866811680","248773863361522599652171128621814619740","119475804019020609841469860958747881060","68354725500214920844510988014111136618","235549796346349065028768555460596998344","61171551586823621510031438140224720671","178396123606223661818039155524466866673"],"threshold":0.9},"id":"CVE-2026-52852-75dbaecb","signature_type":"Line","signature_version":"v1","source":"https://github.com/traccar/traccar/commit/8f6f59ac29d8b1222254e938672a0d99098fd800","target":{"file":"src/main/java/org/traccar/helper/model/AttributeUtil.java"}},{"target":{"file":"src/main/java/org/traccar/api/BaseObjectResource.java"},"deprecated":false,"digest":{"line_hashes":["286910481349003879273935559031795103940","55403599921878598651019405639012821257","198534677675800861057426186922847853093","100175511844442680770614184812786727464","167642237790509170228759108441444613011","43858875385919209061983223682482848194","298174719985997206459758317384824419945","121482855221157524461576046053032358103","149710404917890676829505583260121998766"],"threshold":0.9},"id":"CVE-2026-52852-cb136e48","signature_type":"Line","signature_version":"v1","source":"https://github.com/traccar/traccar/commit/8f6f59ac29d8b1222254e938672a0d99098fd800"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}