{"id":"GHSA-hf44-3mx6-vhhw","summary":"Navigate endpoint is vulnerable to regex injection that may lead to Denial of Service.","details":"### Impact\nThe regex injection that may lead to Denial of Service.\n\n### Patches\nWill be patched in 2.4 and 3.0\n\n### Workarounds\nVersions lower than 2.x are only affected if the navigation module is added\n\n### References\nSee this pull request for the fix: https://github.com/graphhopper/graphhopper/pull/2304\n\nIf you have any questions or comments about this advisory please [send us an Email](https://www.graphhopper.com/contact-form/) or create a topic [here](https://discuss.graphhopper.com/).","aliases":["CVE-2021-29506"],"modified":"2026-05-07T05:01:32.077313145Z","published":"2021-05-19T23:02:57Z","database_specific":{"github_reviewed_at":"2021-05-19T19:49:11Z","nvd_published_at":"2021-05-13T19:15:00Z","cwe_ids":["CWE-400"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/graphhopper/graphhopper/security/advisories/GHSA-hf44-3mx6-vhhw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29506"},{"type":"WEB","url":"https://github.com/graphhopper/graphhopper/pull/2304"},{"type":"WEB","url":"https://github.com/graphhopper/graphhopper/commit/eb189be1fa7443ebf4ae881e737a18f818c95f41"}],"affected":[{"package":{"name":"com.graphhopper:graphhopper-nav","ecosystem":"Maven","purl":"pkg:maven/com.graphhopper/graphhopper-nav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4"}]}],"versions":["2.0","2.0-pre2","2.0-pre3","2.1","2.2","2.3","client_hc_no_vehicle"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-hf44-3mx6-vhhw/GHSA-hf44-3mx6-vhhw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}