Graphhopper develops a routing and optimization engine that serves as a core component in mapping and logistics applications, with its vulnerability footprint concentrating in the primary Graphhopper product around prototype-pollution and resource-consumption weaknesses typical of JavaScript-based or dynamically typed server frameworks. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Graphhopper over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29506MEDIUM GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vulnerability that may lead to De | May 13, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-23408MEDIUM This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Obj | Jul 21, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Graphhopper.
Media articles that mention a CVE ID that affects a product developed by Graphhopper — matched by CVE ID, not by vendor name.